Sensitive Data Leakage Risk in HCL BigFix Quantum Risk Analyzer
CVE-2026-21808

4.1MEDIUM

Key Information:

Vendor
CVE Published:
26 August 2026

What is CVE-2026-21808?

HCL BigFix Quantum Risk Analyzer produces extensive logging information by default, which may inadvertently increase the risk of exposing sensitive data. This logging can reveal critical internal application logic and details about the system's architecture, potentially assisting attackers in executing further compromises. Organizations leveraging this software should consider reconfiguring logging levels to mitigate risks associated with data leakage.

Affected Version(s)

BigFix Quantum Risk Analyzer 2.0.1.47

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.