Junglewise Threat Intelligence

CVE-2025-15633: HCL BigFix WebUI improper authorization in internal endpoints

CVE-2025-15633 · Severity: medium · CVSS 6.5 · Published 2026-05-09

Vendors: HCL Software, HCL.

Executive brief

An authorization flaw in HCL BigFix WebUI allows standard users to access sensitive internal configuration data that should be restricted to administrators. BigFix is an endpoint management platform used to secure and manage corporate devices; this vulnerability could allow a low-privileged user to view site names, software versions, and internal configuration variables. This exposure of internal system details could assist an attacker in planning further unauthorized activities within the network management environment.

Technical details

An improper authorization vulnerability (CWE-863) exists in HCL BigFix WebUI due to unprotected endpoints that lack adequate security headers and privilege checks. An authenticated attacker with low-level privileges can bypass intended access controls to reach internal data, including site names, software versions, and configuration variables. The vulnerability is reachable over the network without user interaction, provided the attacker has valid credentials. HCL has released updates for various WebUI components (e.g., Framework v35, API v33, Common v101) to address these authorization gaps.

Affected products

  • HCL Software BigFix WebUI API < 33
  • HCL Software BigFix WebUI Application Administration < 40
  • HCL Software BigFix WebUI Common < 101
  • HCL Software BigFix WebUI Framework < 35
  • HCL Software BigFix WebUI Patch < 54
  • HCL Software BigFix WebUI Query < 45

Timeline

  • 2026-05-09: disclosed: Initial disclosure by HCL Software
  • 2026-05-09: advisory: NVD publication date

References

Related threats