EUVD Vulnerability Catalog
EUVD-2026-82765
Severity: CRITICAL
Base Score: 9.3
CVSS Version: 3.1
Vulnerability Description
HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Scope (S): Changed
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): Low
▪
Availability Impact (A): None
Affected Vendors & Systems
Vendor
HCL Software
References & Advisory Links
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
HCL
EPSS Probability
0
Known Aliases
CVE-2026-67101
Published On
2026-09-18
Last Updated
2026-09-18