CVE-2026-21809

HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.

Scoring

Severity
LOW
CVSS base score
3.9
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
EPSS probability
0.09%
CWE
CWE-209
Published
2026-08-26
Last modified
2026-08-27

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs