CVE-2026-21785
Awaiting Analysis
Awaiting Analysis - Queue
Misconfigured CSP in HCL BigFix Remote Control Server WebUI
Publication date: 2026-05-27
Last updated on: 2026-06-01
Assigner: HCL Software
Description
Description
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hcl | bigfix_remote_control_server | to 10.1.0.0442 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1021 | The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with. |