CVE-2026-21785
Misconfigured CSP in HCL BigFix Remote Control Server WebUI
Publication date: 2026-05-27
Last updated on: 2026-05-27
Assigner: HCL Software
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hcl | bigfix_remote_control_server | to 10.1.0.0442 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1021 | The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is caused by a misconfigured Content Security Policy (CSP) in the HCL BigFix Remote Control Server WebUI versions 10.1.0.0442 and earlier.
The CSP fails to define directives without fallbacks, which allows attackers to bypass the intended security restrictions.
As a result, attackers can load unauthorized resources that should have been blocked by the CSP.
How can this vulnerability impact me? :
This vulnerability can impact you by allowing attackers to bypass security controls intended to restrict resource loading.
Attackers may load unauthorized or malicious resources within the WebUI, potentially leading to information disclosure or integrity issues.
According to the CVSS score (4.0), the impact includes low confidentiality and integrity impacts, with no impact on availability.