Junglewise Threat Intelligence

CVE-2025-15634: HCL BigFix WebUI missing authorization in multiple components

CVE-2025-15634 · Severity: medium · CVSS 4.3 · Published 2026-05-09

Vendors: HCL Software, HCL.

Executive brief

HCL BigFix WebUI, a management interface for enterprise endpoint security and compliance, is affected by a security flaw that allows low-privileged users to access restricted information. By navigating directly to specific web addresses, an authenticated user can bypass intended access controls to view sensitive details about the IT environment. This could allow unauthorized staff to gain insights into system configurations that they are not permitted to see.

Technical details

A missing authorization vulnerability (CWE-862) exists in multiple components of the HCL BigFix WebUI. The flaw allows an authenticated attacker with low privileges to bypass UI-based access controls by navigating directly to specific URLs that should be restricted. Successful exploitation enables the attacker to view sensitive environmental information, though it does not provide the ability to modify data or disrupt services. The vulnerability affects numerous WebUI modules including the Framework, API, and various application apps (Patch, Software Distribution, etc.) prior to their respective patched versions.

Affected products

  • HCL Software BigFix WebUI API < 33
  • HCL Software BigFix WebUI Application Administration < 40
  • HCL Software BigFix WebUI Framework < 35
  • HCL Software BigFix WebUI Patch < 54
  • HCL Software BigFix WebUI Software Distribution < 54

Timeline

  • 2026-05-09: disclosed: Initial publication of the vulnerability details.
  • 2026-05-09: advisory: HCL Software released a security bulletin (KB0130587).

References

Related threats