CVE-2025-52620: Hcltech Bigfix Saas

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format.

Affected products

  • Hcltech Bigfix Saas: before 8.1.14 (fixed in 8.1.14)

Published 2025-08-15. Last modified 2026-06-17.