CVE-2026-67105
CVE-2026-67105 is a high-severity vulnerability in Hcltech Bigfix Service Management with a CVSS 3.x base score of 7.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-319.
Key facts
- Severity: High (CVSS 3.x base score 7.4)
- EPSS exploit prediction: 0% (4th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-319
- Affected product: Hcltech Bigfix Service Management
- Published:
- Last modified:
Description
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.
Frequently asked questions
- What is CVE-2026-67105?
- HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.
- How severe is CVE-2026-67105?
- CVE-2026-67105 has a CVSS 3.x base score of 7.4, rated high severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-67105 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (4th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-67105?
- CVE-2026-67105 affects Hcltech Bigfix Service Management. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-67105?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-67105 published?
- CVE-2026-67105 was published on 2026-10-01 and last updated on 2026-10-05.
References
Affected products (1)
- cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*
More vulnerabilities in Hcltech Bigfix Service Management
- CVE-2024-30151 — High (CVSS 8.3): HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege…
- CVE-2026-56589 — High (CVSS 7.2): HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an…
- CVE-2025-31972 — Medium (CVSS 6.5): HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS…
- CVE-2026-67171 — Medium (CVSS 5.3): HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint…
- CVE-2026-67106 — Medium (CVSS 5.3): HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints…
- CVE-2026-67104 — Medium (CVSS 5.3): HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an…
All CVEs affecting Hcltech Bigfix Service Management →
Other CWE-319 (Cleartext Transmission of Sensitive Information) vulnerabilities
- CVE-2026-22306 — Critical (CVSS 10.0): Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext…
- CVE-2025-4378 — Critical (CVSS 10.0): Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University…
- CVE-2025-47419 — Critical (CVSS 10.0): Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network…
- CVE-2026-69658 — Critical (CVSS 9.8): MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level…
- CVE-2026-48902 — Critical (CVSS 9.8): The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't…
- CVE-2025-34271 — Critical (CVSS 9.8): Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when…
Browse all CWE-319 (Cleartext Transmission of Sensitive Information) vulnerabilities →