Description
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.
Published: 2026-08-26
Score: 4.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from a hardcoded external resource reference and the absence of binary integrity validation. This flaw permits an attacker to replace or tamper with code that the application retrieves, potentially enabling extraction of sensitive information or insertion of malicious logic into the executable. Consequently, the primary risk is a loss of data confidentiality and alteration of the application’s integrity.

Affected Systems

The affected product is HCL BigFix Quantum Risk Analyzer. Vendor information is HCLSoftware. No specific versions are listed, so any running instance of this product may be vulnerable unless already updated.

Risk and Exploitability

The CVSS score of 4.4 signals a moderate severity. EPSS data is unavailable and the issue is not on the CISA KEV list, suggesting a lower current exploitation likelihood, yet the vulnerability enables remote modification or exposure of data simply by controlling the application’s external resource fetching. The likely attack vector is remote via the application’s download capability, inferred from the description.

Generated by OpenCVE AI on August 26, 2026 at 23:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review and apply the latest HCL Software security advisory for BigFix Quantum Risk Analyzer to install any available patch or update
  • If no patch is available, restrict the application’s outbound connectivity to trusted hosts and disable external resource loading if a configuration option exists
  • Monitor the system for unexpected outbound connections or binary changes, and verify the binary’s integrity using vendor‑supplied checksums when possible

Generated by OpenCVE AI on August 26, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.
Title HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and downloading code without integrity checking
Weaknesses CWE-494
CWE-610
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-26T21:55:07.970Z

Reserved: 2026-01-05T16:08:06.683Z

Link: CVE-2026-21810

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T22:16:23.447

Modified: 2026-08-26T22:16:23.447

Link: CVE-2026-21810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T23:30:12Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check

  • CWE-610

    Externally Controlled Reference to a Resource in Another Sphere