Description
HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service.
Published: 2026-07-14
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to infer the existence of specific user accounts on HCL BigFix Platform by observing differences in response times. This information can be used for credential guessing or social engineering, but it does not provide direct access to data or code execution. The weakness corresponds to CWE‑208: Information Exposure Through Inadequate Log Message Filtering.

Affected Systems

HCL Software’s HCL BigFix Platform is the affected product. The CVE data does not specify vulnerable versions, so all deployments of the platform are potentially at risk until a patch is applied.

Risk and Exploitability

The CVSS score of 3.1 indicates low severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to send requests and monitor response times, typically performing a timing attack to infer account existence. No privilege escalation or remote code execution is possible, but the disclosed information can aid credential guessing or social engineering attacks.

Generated by OpenCVE AI on July 31, 2026 at 04:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HCL BigFix Platform security patch released through the official HCL advisory.
  • Restrict access to BigFix services to trusted hosts via network segmentation and firewall rules.
  • Implement response‑time throttling and rate limiting on account‑lookup endpoints to mitigate enumeration attempts.

Generated by OpenCVE AI on July 31, 2026 at 04:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech bigfix Platform
Vendors & Products Hcltech
Hcltech bigfix Platform

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service.
Title HCL BigFix Platform is affected by a user enumeration vulnerability
Weaknesses CWE-208
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hcltech Bigfix Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-15T12:46:19.073Z

Reserved: 2026-01-05T16:08:25.001Z

Link: CVE-2026-21840

cve-icon Vulnrichment

Updated: 2026-07-15T12:45:26.341Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:03Z

Weaknesses
  • CWE-208

    Observable Timing Discrepancy