CVE-2025-52618: Hcltech Bigfix Saas

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential attackers to manipulate SQL queries.

Affected products

  • Hcltech Bigfix Saas: before 8.1.14 (fixed in 8.1.14)

Published 2025-08-15. Last modified 2026-06-17.