Home

Description

A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.

PUBLISHED Reserved 2026-01-05 | Published 2026-05-27 | Updated 2026-05-28 | Assigner HCL




MEDIUM: 4.0CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-1021 Improper restriction of rendered UI layers or frames

Product status

Default status
unaffected

<= versions 10.1.0.0442
affected

References

support.hcl-software.com/...rticle&sysparm_article=KB0130581

cve.org (CVE-2026-21785)

nvd.nist.gov (CVE-2026-21785)

Download JSON