Junglewise Threat Intelligence

CVE-2026-21808: HCL BigFix Quantum Risk Analyzer verbose logging information disclosure

CVE-2026-21808 · Severity: medium · CVSS 4.1 · Published 2026-08-26

Executive brief

HCL BigFix Quantum Risk Analyzer is a risk assessment and compliance management tool used to identify and manage security vulnerabilities across IT infrastructure. By default, the application generates highly detailed logs that expose sensitive information including internal application logic, architectural details, and potentially confidential business data—creating a significant risk if logs are accessed by unauthorized parties or attackers.

Technical details

This vulnerability is an information disclosure issue caused by overly verbose logging enabled by default in HCL BigFix Quantum Risk Analyzer. The application logs sensitive details about its internal architecture, application logic, and operational data without adequate filtering or suppression. An attacker with access to logs (via misconfigured storage, unauthorized file access, or log aggregation systems) can extract architectural knowledge and sensitive information to facilitate further attacks. There are no preconditions for access beyond obtaining the log files themselves. Patches or configuration changes to disable verbose logging by default are expected to be available from HCL.

Affected products

  • HCL BigFix Quantum Risk Analyzer

Timeline

  • 2026-08-26: disclosed

References

Related threats