OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-56589 (CVSS 7.2)

NVD · officialPublished Oct 1, 2026Risk 23/100

HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page, enabling session hijacking and the theft of sensitive data.

CVSS
7.2
AV:NetworkAC:LowPR:NoneUI:NoneC:LowI:LowA:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source