CVE-2026-21840 LOW

CVE-2026-21840: HCL BigFix Platform is affected by a user enumeration vulnerability

Vendor Hclsoftware
Product HCL BigFix Platform
Weakness CWE-208
Published July 14, 2026
Last update July 14, 2026

CVSS base score

3.1/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service.

Key dates

02Disclosure timeline

July 14, 2026 CVE published