Description
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details.
Published: 2026-08-26
Score: 4.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the default logging configuration of HCL BigFix Quantum Risk Analyzer, which records highly detailed activity. This excessive detail can expose sensitive data and internal application logic to anyone with access to the logs, thereby compromising confidentiality and potentially aiding attackers in understanding the system architecture.

Affected Systems

The affected product is HCL Software’s BigFix Quantum Risk Analyzer. No specific version range is listed in the available data.

Risk and Exploitability

The CVSS score of 4.1 indicates moderate severity. The exploit probability is not quantified (EPSS not available), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers would require access to the system’s log files, which may be achievable by a privileged user or a compromised local account. Once accessed, the logs could provide actionable insights into the application’s internal structure.

Generated by OpenCVE AI on August 27, 2026 at 00:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure the application to reduce logging detail to the minimum necessary level.
  • Ensure log files are stored in a secure location with permissions restricted to privileged users only.
  • Apply any vendor patches or updates that address logging configuration issues.

Generated by OpenCVE AI on August 27, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Description HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details.
Title HCL BigFix Quantum Risk Analyzer is affected by logging sensitive information
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-26T22:03:20.294Z

Reserved: 2026-01-05T16:08:06.682Z

Link: CVE-2026-21808

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T23:17:12.833

Modified: 2026-08-26T23:17:12.833

Link: CVE-2026-21808

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T00:30:14Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File