CVE-2025-15633 PUBLISHED

HCL BigFix WebUI is affected by an improper authorization vulnerability

Assigner: HCL
Reserved: 14.04.2026 Published: 09.05.2026 Updated: 09.05.2026

An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor HCLSoftware
Product BigFix WebUI
Versions Default: unaffected
  • Version all versions is affected

References

Problem Types

  • CWE-863 Incorrect Authorization CWE