CVE-2026-21765
HCL BigFix Server vulnerability analysis and mitigation

Overview

CVE-2026-21765 is a vulnerability in HCL BigFix Platform caused by insecure file system permissions on private cryptographic keys stored on Windows host machines. The flaw allows low-privileged local users to access sensitive cryptographic material due to overly permissive default permissions. It affects HCL BigFix Platform versions 11.0.0 through 11.0.5. The vulnerability was published on April 2, 2026, with a CVSS v3.1 base score of 8.8 (High) per the GitHub Advisory Database, or 7.8 (High) per NVD (GitHub Advisory, Feedly).

Technical details

The root cause is classified under CWE-276 (Incorrect Default Permissions) and CWE-732 (Incorrect Permission Assignment for Critical Resource), meaning the installation process sets file system permissions on private cryptographic key files that are broader than necessary. A local attacker with low privileges on a Windows host running HCL BigFix Platform can enumerate and read these key files without requiring elevated rights or user interaction. The attack vector is local, with low complexity, and no user interaction is required, making exploitation straightforward for any authenticated local user (GitHub Advisory, HCL Advisory).

Impact

Successful exploitation allows an attacker with low-privileged local access to read private cryptographic keys used by HCL BigFix Platform, enabling decryption of sensitive communications, forgery of cryptographic signatures, and potential impersonation of the BigFix server or clients. The ENISA scoring (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) reflects a scope change, indicating that compromise of the cryptographic keys could affect systems beyond the immediately vulnerable host — including managed endpoints and connected BigFix infrastructure. Confidentiality, integrity, and availability are all rated High (GitHub Advisory, Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.015% (3rd percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory, Feedly).

Exploitation steps

  1. Local Access: Obtain a low-privileged user account on a Windows host running HCL BigFix Platform versions 11.0.0–11.0.5.
  2. Reconnaissance: Use file and directory discovery tools (e.g., icacls, Get-Acl in PowerShell, or dir /q) to enumerate file system permissions on BigFix Platform installation directories, identifying cryptographic key files with overly permissive ACLs (e.g., readable by all authenticated users or Everyone).
  3. Key Extraction: Copy or read the private cryptographic key files directly from the file system using standard file access commands, since permissions do not restrict low-privileged users.
  4. Cryptographic Abuse: Use the extracted private keys to decrypt intercepted BigFix communications, forge signed messages or certificates, or impersonate the BigFix server/relay to managed endpoints, potentially enabling lateral movement across the managed environment (GitHub Advisory, HCL Advisory).

Indicators of compromise

  • File System: Unexpected access or modification timestamps on private key files in the HCL BigFix Platform installation directory (e.g., C:\Program Files\BigFix Enterprise\).
  • Logs: Windows Security Event Log entries (Event ID 4663) showing low-privileged accounts accessing cryptographic key files outside of normal BigFix service account activity.
  • Process: Unusual processes (e.g., cmd.exe, powershell.exe, certutil.exe) accessing BigFix key file paths, spawned by non-service user accounts.
  • Network: Unexpected or anomalous TLS/SSL sessions originating from non-BigFix hosts using BigFix server certificates, which may indicate key misuse or impersonation attempts.

Mitigation and workarounds

HCL has released a patch addressing this vulnerability; users should apply the fix referenced in the HCL support knowledge base article KB0129906. As an immediate workaround, administrators should audit and restrict file system permissions on private cryptographic key directories and files on all Windows hosts running BigFix Platform, limiting access to the BigFix service account and local administrators only. Additionally, monitor for unauthorized access to key file locations and consider implementing Windows auditing (SACL) on those files to detect future access attempts (HCL Advisory, GitHub Advisory).

Community reactions

The vulnerability received coverage from The Hacker Wire and was indexed by several vulnerability tracking platforms including VulDB, INCIBE-CERT, and ENISA's EUVD shortly after disclosure. No significant researcher commentary or notable community debate has been observed beyond standard vulnerability aggregation and reporting (The Hacker Wire).

Additional resources


SourceThis report was generated using AI

Related HCL BigFix Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21765HIGH7.8
  • HCL BigFix Server logoHCL BigFix Server
  • cpe:2.3:a:hcltech:bigfix_platform
NoNoApr 02, 2026
CVE-2024-42189MEDIUM5.6
  • HCL BigFix Server logoHCL BigFix Server
  • cpe:2.3:a:hcltech:bigfix_platform
NoYesApr 15, 2025
CVE-2024-42200MEDIUM4.8
  • HCL BigFix Server logoHCL BigFix Server
  • cpe:2.3:a:hcltech:bigfix_platform
NoYesApr 15, 2025
CVE-2026-21767LOW3.3
  • HCL BigFix Server logoHCL BigFix Server
  • cpe:2.3:a:hcltech:bigfix_platform
NoNoApr 02, 2026
CVE-2024-42193LOW2.1
  • HCL BigFix Server logoHCL BigFix Server
  • cpe:2.3:a:hcltech:bigfix_platform
NoYesApr 15, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management