HCL BigFix RunBookAI Unvalidated Command Input Vulnerability Allowing Unauthorized Command Execution
Vulnerability
A vulnerability allowing unvalidated command input has been identified in HCL BigFix RunBookAI v11.1. This flaw could enable unauthorized execution of commands by exploiting a weakness in how the application handles input.
Impact
Exploitation of this vulnerability could lead to unauthorized command execution on the affected system.
Remediation
Users can upgrade to HCL BigFix RunBookAI v11.2, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL BigFix RunBookAI support team.
Added: May 6, 2026, 6:15 PM
Updated: May 6, 2026, 6:15 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
7.5exploitability
5.2remediation
0.0relevance
7.6threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
