CVE-2026-21809: HCL BigFix Quantum Risk Analyzer is affected by generating error messages with sensitive information
Published Aug 26, 2026
·Updated
HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.
Affected Software
1 affected component
HCL BigFix Quantum Risk Analyzer
Event History
Aug 26, 2026
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access and effort does exploitation require?
Exploitation requires local access, high privileges, and high attack complexity. No user interaction is required.
2
What information could be exposed or affected?
The available data indicates low-impact effects on confidentiality, integrity, and availability. The issue exposes overly descriptive validation error messages that can help an attacker perform reconnaissance and refine fuzzing inputs.