Junglewise Threat Intelligence

CVE-2026-21807: HCL BigFix Quantum Risk Analyzer stack buffer overflow

CVE-2026-21807 · Severity: low · CVSS 3.9 · Published 2026-08-26

Executive brief

HCL BigFix Quantum Risk Analyzer is an enterprise risk assessment tool used to identify security vulnerabilities in IT environments. The software binary lacks standard security hardening protections, which could allow an attacker to trigger a stack-based buffer overflow and potentially crash the application or execute arbitrary code.

Technical details

The vulnerability is a stack-based buffer overflow resulting from missing industry-standard binary hardening protections such as ASLR, DEP/NX, or stack canaries. The vulnerable component is the BigFix Quantum Risk Analyzer binary itself. An attacker with the ability to supply specially crafted input to the application could overflow the stack buffer, potentially achieving code execution or denial of service. The attack vector and required preconditions are not fully detailed in the available advisory text. A patch or fix may be available from HCL support.

Affected products

  • HCL BigFix Quantum Risk Analyzer

Timeline

  • 2026-08-26: disclosed

References

Related threats