CVE-2025-15633: Hcltech Bigfix Webui API
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.
Affected products
- Hcltech Bigfix Webui API: before 33 (fixed in 33)
- Hcltech Bigfix Webui Application Administration: before 40 (fixed in 40)
- Hcltech Bigfix Webui Cmep: before 22 (fixed in 22)
- Hcltech Bigfix Webui Common: before 101 (fixed in 101)
- Hcltech Bigfix Webui Content App: before 28 (fixed in 28)
- Hcltech Bigfix Webui Custom: before 50 (fixed in 50)
- Hcltech Bigfix Webui Data Sync: before 37 (fixed in 37)
- Hcltech Bigfix Webui Extensions: before 14 (fixed in 14)
- Hcltech Bigfix Webui Framework: before 35 (fixed in 35)
- Hcltech Bigfix Webui Insights: before 32 (fixed in 32)
- Hcltech Bigfix Webui Ivr: before 23 (fixed in 23)
- Hcltech Bigfix Webui Mdm: before 29 (fixed in 29)
- Hcltech Bigfix Webui Patch: before 54 (fixed in 54)
- Hcltech Bigfix Webui Patch Policies: before 51 (fixed in 51)
- Hcltech Bigfix Webui Permissions And Preferences: before 27 (fixed in 27)
- Hcltech Bigfix Webui Profile Management: before 33 (fixed in 33)
- Hcltech Bigfix Webui Query: before 45 (fixed in 45)
- Hcltech Bigfix Webui Reports: before 24 (fixed in 24)
- Hcltech Bigfix Webui Scm: before 20 (fixed in 20)
- Hcltech Bigfix Webui Software Distribution: before 54 (fixed in 54)
- Hcltech Bigfix Webui Take Action: before 37 (fixed in 37)
Published 2026-05-09. Last modified 2026-07-25.