← Back

CVE-2026-35148

nvd nist
Published: Jul 16, 2026Modified: Jul 21, 2026

JSON object

Loading...
6.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Exploitability: 2.8 / Impact: 3.4
Source: psirt@hcl.com (Secondary)

Description

HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.

Affected (1)

Products: Hcltech: Dfx Server
1 product
Dfx Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.5

Timeline

No history available yet.