Junglewise Threat Intelligence

CVE-2026-21840: HCL BigFix Platform user enumeration via timing discrepancy

CVE-2026-21840 · Severity: low · CVSS 3.1 · Published 2026-07-14

Vendors: HCL Software.

Executive brief

HCL BigFix Platform, a tool used for managing and securing large numbers of computers, is affected by a security flaw that could allow an attacker to identify valid usernames on the system. By monitoring how long the server takes to respond to different requests, an unauthorized person could map out existing user accounts. While this does not grant direct access to data, it provides a list of targets that could be used for more targeted password-guessing or phishing attacks.

Technical details

HCL BigFix Platform is vulnerable to user enumeration via an observable timing discrepancy (CWE-208). An attacker with low-privileged network access can monitor server response times to distinguish between valid and invalid usernames. This side-channel attack requires high complexity to execute effectively but can result in the disclosure of valid account names. The vulnerability affects versions 10.0.0 through 10.0.15 and 11.0.0 through 11.0.5. Users are advised to refer to HCL security bulletin KB0132093 for remediation steps.

Affected products

  • HCL Software BigFix Platform 10.0.0 - 10.0.15, 11.0.0 - 11.0.5

Timeline

  • 2026-07-14: disclosed: Initial publication of the CVE record.
  • 2026-07-14: advisory: HCL Software published security bulletin KB0132093.

References