PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-21785 HCLSoftware CVE debrief

A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources. The vulnerability was published on 2026-05-27 with a CVSS 3.1 score of 4.0 (MEDIUM severity). The attack vector is network-based with high attack complexity, requiring high privileges and user interaction, with scope change impact. The confidentiality and integrity impacts are rated low, with no availability impact. The weakness is categorized as CWE-1021 (Improper Restriction of Rendered UI Layers or Frames). HCL Software has published a knowledge base article addressing this issue.

Vendor
HCLSoftware
Product
BigFix Remote Control Server
CVSS
MEDIUM 4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-27
Original CVE updated
2026-05-27
Advisory published
2026-05-27
Advisory updated
2026-05-27

Who should care

Organizations running HCL BigFix Remote Control Server WebUI version 10.1.0.0442 or earlier, particularly those with administrative interfaces exposed to network access. Security teams responsible for web application security and CSP configuration management should prioritize review.

Technical summary

The HCL BigFix Remote Control Server WebUI versions 10.1.0.0442 and earlier contain a Content Security Policy misconfiguration where directives lack proper fallback definitions. This allows attackers with high privileges and user interaction to bypass security restrictions and load unauthorized resources. The vulnerability requires network access and high attack complexity, with potential for low-impact confidentiality and integrity breaches through scope-changed attacks.

Defensive priority

medium

Recommended defensive actions

  • Review and update Content Security Policy configurations in HCL BigFix Remote Control Server WebUI to ensure all directives include appropriate fallback mechanisms
  • Upgrade to a version newer than 10.1.0.0442 when available per vendor guidance
  • Audit CSP headers for missing default-src or other fallback directives that could allow unauthorized resource loading
  • Monitor for anomalous resource loading attempts in WebUI access logs
  • Apply principle of least privilege for administrative access to reduce attack surface given high privilege requirements

Evidence notes

CVE description confirms CSP misconfiguration in HCL BigFix Remote Control Server WebUI ≤10.1.0.0442. CVSS 3.1 vector: AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N. CWE-1021 identified. Vendor attribution based on reference domain candidate 'HCL Software' with low confidence requiring review.

Official resources

2026-05-27