← All CVEs

CVE-2026-67101

critical · 9.3

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet.

9.3
CVSS
0.3%
EPSS (exploit prob.)
19th
EPSS percentile
2026-09-18
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

Weaknesses

CWE-918

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-67101