# CVE-2026-21785

## Summary

- **CVE ID:** CVE-2026-21785
- **Severity:** MEDIUM
- **CVSS Score:** 4 (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N)
- **CWE:** CWE-1021
- **Published:** May 27, 2026
- **Last Modified:** May 28, 2026

## Description

A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.

## Affected Products

- HCLSoftware — BigFix Remote Control Server (<= versions 10.1.0.0442)

## References

- [CNA](https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130581)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._