PT-2026-39320 · Hclsoftware · Bigfix Webui

Published

2026-05-09

·

Updated

2026-05-09

·

CVE-2025-15633

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-15633

Affected Products

Bigfix Webui