SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-21840

LOW · CVSS 3.1 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The HCL BigFix Platform is vulnerable to a user enumeration flaw that could enable an attacker to identify valid usernames by analyzing system responses and timing. While the severity is classified as low, organizations using this platform should prioritize remediation to prevent potential credential enumeration attacks. System administrators and security teams should be particularly vigilant in monitoring user access and response behaviors.

CVE
CVE-2026-21840
Severity
LOW
CVSS
3.1
EPSS
0.15%

Original NVD Description

HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service.