CVE-2026-21840: Hclsoftware Hcl Bigfix Platform

Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service.

Affected products

Published 2026-07-14. Last modified 2026-07-15.