CVE-2026-21810: HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and downloading code without integrity checking
Published Aug 26, 2026
·Updated
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.
Affected Software
1 affected component
HCL BigFix Quantum Risk Analyzer
Event History
Aug 26, 2026
CVE Published
via MITRE·09:55 PM
Data Sourced
via MITRE·09:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access would an attacker need to exploit this issue?
The CVSS vector indicates that exploitation requires local access and high privileges. It does not require user interaction.
2
What is the primary security impact indicated by the available scoring data?
The available CVSS data indicates a high integrity impact, meaning an attacker could modify affected content or binaries. No confidentiality or availability impact is reflected in the vector.