CVE-2026-21809

Summary

HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.

Affected Software

VendorProductVersion RangeStatus
HCLSoftwareBigFix Quantum Risk Analyzer2.0.1.47affected

Weaknesses

  • CWE-209: CWE-209 Generation of error message containing sensitive information

References