HCL BigFix RunBookAI Unvalidated Command Input Vulnerability Allowing Unauthorized Command Execution

Vulnerability

A vulnerability allowing unvalidated command input has been identified in HCL BigFix RunBookAI v11.1. This flaw could enable unauthorized execution of commands by exploiting a weakness in how the application handles input.

Impact

Exploitation of this vulnerability could lead to unauthorized command execution on the affected system.

Remediation

Users can upgrade to HCL BigFix RunBookAI v11.2, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL BigFix RunBookAI support team.

Added: May 6, 2026, 6:15 PM
Updated: May 6, 2026, 6:15 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
0.0
relevance
7.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.