Vulnerability Details CVE-2026-67105
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 4.0%
CVSS Severity
CVSS v3 Score 7.4
Products affected by CVE-2026-67105
-
cpe:2.3:a:hcltech:bigfix_service_management:27