CVE-2026-21810CWE-494CWE-610

CVE-2026-21810

Medium · published August 27, 2026

CVSS v3.1
4.4
EPSS
0%
Percentile
0.1
In the wild
Unconfirmed
What it is

HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.

The record
Technical detail
CVSS v3.1
4.4 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00074 · 0.1th percentile
Weaknesses
CWE-494 · Download of Code Without Integrity Check; CWE-610 · Externally Controlled Reference to a Resource in Another Sphere
Published
2026-08-27T02:16Z
References (1)
EPSS history
Timeline
  • 28 AUG 06:33Z
    EPSS moved — → 0%
    epss
  • 26 AUG 21:55Z
    HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and downloading code without integrity checking
    cvelistv5