← Vulnerability feed

Vulnerability record · CVE-2026-21765 · published 2 April 2026

CVE-2026-21765: Hcltech bigfix platform incorrect default permissions vulnerability

Hcltech · Bigfix Platform

HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.

7.8 CVSS 3.1 High EPSS 0.10% · top 99.2% CWE-276 · Incorrect default permissionsCWE-732 · Incorrect permission assignment
7.8CVSS 3.1 base score
0.10%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21765 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27762Hcltech bigfix platform vulnerabilityMisconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responsesEPSS 0.72%8.8CVE-2024-23554Hcltech bigfix platform cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).EPSS 0.27%8.8CVE-2023-37536Apache xerces-c\+\+ integer overflow vulnerabilityAn integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.EPSS 1.4%7.8CVE-2022-38659Hcltech bigfix platform inadequate encryption strength vulnerabilityIn specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.EPSS 0.13%7.8CVE-2021-27765Hcltech bigfix platform improper privilege management vulnerabilityThe BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to…EPSS 0.34%7.8CVE-2021-27766Hcltech bigfix platform improper privilege management vulnerabilityThe BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to per…EPSS 0.19%7.8CVE-2021-27767Hcltech bigfix platform improper privilege management vulnerabilityThe BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to pe…EPSS 0.19%7.5CVE-2024-23556Hcltech bigfix platform vulnerabilitySSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2026-21765), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.