CVE Feed

    Dashboard / CVE / CVE-2025-15633

    CVE-2025-15633

    An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.

    Published:May 9, 2026
    Last Modified:May 14, 2026
    EPS:May 9, 2026
    EPSS Score:0.00038
    CVSS Score:6.5

    Affected Products

    Vendor
    Hcltech
    Product
    Bigfix Webui
    Vendor
    Hcltech
    Product
    Bigfix Webui Api
    Vendor
    Hcltech
    Product
    Bigfix Webui Application Administration
    Vendor
    Hcltech
    Product
    Bigfix Webui Cmep
    Vendor
    Hcltech
    Product
    Bigfix Webui Common
    Vendor
    Hcltech
    Product
    Bigfix Webui Content App
    Vendor
    Hcltech
    Product
    Bigfix Webui Custom
    Vendor
    Hcltech
    Product
    Bigfix Webui Data Sync
    Vendor
    Hcltech
    Product
    Bigfix Webui Extensions
    Vendor
    Hcltech
    Product
    Bigfix Webui Framework
    Vendor
    Hcltech
    Product
    Bigfix Webui Insights
    Vendor
    Hcltech
    Product
    Bigfix Webui Ivr
    Vendor
    Hcltech
    Product
    Bigfix Webui Mdm
    Vendor
    Hcltech
    Product
    Bigfix Webui Patch
    Vendor
    Hcltech
    Product
    Bigfix Webui Patch Policies
    Vendor
    Hcltech
    Product
    Bigfix Webui Permissions And Preferences
    Vendor
    Hcltech
    Product
    Bigfix Webui Profile Management
    Vendor
    Hcltech
    Product
    Bigfix Webui Query
    Vendor
    Hcltech
    Product
    Bigfix Webui Reports
    Vendor
    Hcltech
    Product
    Bigfix Webui Scm
    Vendor
    Hcltech
    Product
    Bigfix Webui Software Distribution
    Vendor
    Hcltech
    Product
    Bigfix Webui Take Action

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High