CVE-2026-21785
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N
- EPSS probability
- 0.15%
- CWE
- CWE-1021
- Published
- 2026-05-27
- Last modified
- 2026-05-28
Affected products
- HCLSoftware BigFix Remote Control Server
Weakness type
Related vulnerabilities
- CVE-2026-87995 — Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
- CVE-2026-87538 — Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had...
- CVE-2026-87655 — Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87486 — Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed...
- CVE-2026-75548 — Ebyte NA111-M Improper Restriction of Rendered UI Layers or Frames
- CVE-2026-18534 — Address bar spoofing risk in affected iOS versions of Arc Search
- CVE-2026-44762 — Security Misconfiguration in SAP Data Services Management Console
- CVE-2026-70608 — Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path