PatchSiren cyber security CVE debrief
CVE-2026-21785 HCLSoftware CVE debrief
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources. The vulnerability was published on 2026-05-27 with a CVSS 3.1 score of 4.0 (MEDIUM severity). The attack vector is network-based with high attack complexity, requiring high privileges and user interaction, with scope change impact. The confidentiality and integrity impacts are rated low, with no availability impact. The weakness is categorized as CWE-1021 (Improper Restriction of Rendered UI Layers or Frames). HCL Software has published a knowledge base article addressing this issue.
- Vendor
- HCLSoftware
- Product
- BigFix Remote Control Server
- CVSS
- MEDIUM 4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-05-27
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-05-27
Who should care
Organizations running HCL BigFix Remote Control Server WebUI version 10.1.0.0442 or earlier, particularly those with administrative interfaces exposed to network access. Security teams responsible for web application security and CSP configuration management should prioritize review.
Technical summary
The HCL BigFix Remote Control Server WebUI versions 10.1.0.0442 and earlier contain a Content Security Policy misconfiguration where directives lack proper fallback definitions. This allows attackers with high privileges and user interaction to bypass security restrictions and load unauthorized resources. The vulnerability requires network access and high attack complexity, with potential for low-impact confidentiality and integrity breaches through scope-changed attacks.
Defensive priority
medium
Recommended defensive actions
- Review and update Content Security Policy configurations in HCL BigFix Remote Control Server WebUI to ensure all directives include appropriate fallback mechanisms
- Upgrade to a version newer than 10.1.0.0442 when available per vendor guidance
- Audit CSP headers for missing default-src or other fallback directives that could allow unauthorized resource loading
- Monitor for anomalous resource loading attempts in WebUI access logs
- Apply principle of least privilege for administrative access to reduce attack surface given high privilege requirements
Evidence notes
CVE description confirms CSP misconfiguration in HCL BigFix Remote Control Server WebUI ≤10.1.0.0442. CVSS 3.1 vector: AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N. CWE-1021 identified. Vendor attribution based on reference domain candidate 'HCL Software' with low confidence requiring review.
Official resources
-
CVE-2026-21785 CVE record
CVE.org
-
CVE-2026-21785 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
2026-05-27