HCL BigFix WebUI Improper Authorization Vulnerability Allowing Data Access and Privilege Bypass

Vulnerability

A vulnerability in HCL BigFix WebUI exists that allows an authenticated user without Master Operator privileges to access internal data, such as site names, versions, and configuration variables. This is achieved by exploiting unprotected endpoints that lack adequate security headers, thereby bypassing privilege requirements.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive internal data and the ability to bypass established privilege requirements, potentially allowing users to perform actions or access information they should not be entitled to.

Remediation

Users are advised to upgrade to the latest version of HCL BigFix WebUI. Specific version recommendations can be found in the HCL BigFix WebUI Security Bulletin.

Added: May 9, 2026, 6:24 AM
Updated: May 9, 2026, 6:24 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.3
exploitability
3.5
remediation
7.7
relevance
7.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.