CVE 4 MEDIUM

HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content Security Policy_CVE-2026-21785

4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N

Description

A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.

Basic Information

ID CVE-2026-21785
Source HCL
Published May 27, 2026 at 20:15

Affected Product

Vendor HCLSoftware
Product BigFix Remote Control Server
Version <= versions 10.1.0.0442
Affected Versions HCLSoftware BigFix Remote Control Server <= versions 10.1.0.0442

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.