CVE-2026-67100
CRITICAL
NVD
CVSS Score
9.8
Severity
CRITICAL
Published
Sep 18, 2026
Vendor
unknown
Description
HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations.