CVE-2025-31959: Hcltech Bigfix Service Management

Low severity, CVSS 3.5. EPSS: 0.1% chance of exploitation in the next 30 days.

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .

Affected products

  • Hcltech Bigfix Service Management: version 23.0 only

Published 2026-05-06. Last modified 2026-10-07.