
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21765 is a vulnerability in HCL BigFix Platform caused by insecure file system permissions on private cryptographic keys stored on Windows host machines. The flaw allows low-privileged local users to access sensitive cryptographic material due to overly permissive default permissions. It affects HCL BigFix Platform versions 11.0.0 through 11.0.5. The vulnerability was published on April 2, 2026, with a CVSS v3.1 base score of 8.8 (High) per the GitHub Advisory Database, or 7.8 (High) per NVD (GitHub Advisory, Feedly).
The root cause is classified under CWE-276 (Incorrect Default Permissions) and CWE-732 (Incorrect Permission Assignment for Critical Resource), meaning the installation process sets file system permissions on private cryptographic key files that are broader than necessary. A local attacker with low privileges on a Windows host running HCL BigFix Platform can enumerate and read these key files without requiring elevated rights or user interaction. The attack vector is local, with low complexity, and no user interaction is required, making exploitation straightforward for any authenticated local user (GitHub Advisory, HCL Advisory).
Successful exploitation allows an attacker with low-privileged local access to read private cryptographic keys used by HCL BigFix Platform, enabling decryption of sensitive communications, forgery of cryptographic signatures, and potential impersonation of the BigFix server or clients. The ENISA scoring (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) reflects a scope change, indicating that compromise of the cryptographic keys could affect systems beyond the immediately vulnerable host — including managed endpoints and connected BigFix infrastructure. Confidentiality, integrity, and availability are all rated High (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.015% (3rd percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory, Feedly).
icacls, Get-Acl in PowerShell, or dir /q) to enumerate file system permissions on BigFix Platform installation directories, identifying cryptographic key files with overly permissive ACLs (e.g., readable by all authenticated users or Everyone).C:\Program Files\BigFix Enterprise\).cmd.exe, powershell.exe, certutil.exe) accessing BigFix key file paths, spawned by non-service user accounts.HCL has released a patch addressing this vulnerability; users should apply the fix referenced in the HCL support knowledge base article KB0129906. As an immediate workaround, administrators should audit and restrict file system permissions on private cryptographic key directories and files on all Windows hosts running BigFix Platform, limiting access to the BigFix service account and local administrators only. Additionally, monitor for unauthorized access to key file locations and consider implementing Windows auditing (SACL) on those files to detect future access attempts (HCL Advisory, GitHub Advisory).
The vulnerability received coverage from The Hacker Wire and was indexed by several vulnerability tracking platforms including VulDB, INCIBE-CERT, and ENISA's EUVD shortly after disclosure. No significant researcher commentary or notable community debate has been observed beyond standard vulnerability aggregation and reporting (The Hacker Wire).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."