CVE-2025-15634: Hcltech Bigfix Webui API

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.

Affected products

  • Hcltech Bigfix Webui API: before 33 (fixed in 33)
  • Hcltech Bigfix Webui Application Administration: before 40 (fixed in 40)
  • Hcltech Bigfix Webui Cmep: before 22 (fixed in 22)
  • Hcltech Bigfix Webui Common: before 101 (fixed in 101)
  • Hcltech Bigfix Webui Content App: before 28 (fixed in 28)
  • Hcltech Bigfix Webui Custom: before 50 (fixed in 50)
  • Hcltech Bigfix Webui Data Sync: before 37 (fixed in 37)
  • Hcltech Bigfix Webui Extensions: before 14 (fixed in 14)
  • Hcltech Bigfix Webui Framework: before 35 (fixed in 35)
  • Hcltech Bigfix Webui Insights: before 32 (fixed in 32)
  • Hcltech Bigfix Webui Ivr: before 23 (fixed in 23)
  • Hcltech Bigfix Webui Mdm: before 29 (fixed in 29)
  • Hcltech Bigfix Webui Patch: before 54 (fixed in 54)
  • Hcltech Bigfix Webui Patch Policies: before 51 (fixed in 51)
  • Hcltech Bigfix Webui Permissions And Preferences: before 27 (fixed in 27)
  • Hcltech Bigfix Webui Profile Management: before 33 (fixed in 33)
  • Hcltech Bigfix Webui Query: before 45 (fixed in 45)
  • Hcltech Bigfix Webui Reports: before 24 (fixed in 24)
  • Hcltech Bigfix Webui Scm: before 20 (fixed in 20)
  • Hcltech Bigfix Webui Software Distribution: before 54 (fixed in 54)
  • Hcltech Bigfix Webui Take Action: before 37 (fixed in 37)

Published 2026-05-09. Last modified 2026-07-25.