CVE-2026-35149
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Exploitability: 3.9 / Impact: 4.2
Source: psirt@hcl.com (Secondary)
Description
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.
Affected (1)
Products: Hcltech: Dfx Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.5 |
References (1)
Source: psirt@hcl.com
Vendor Advisory
Timeline
No history available yet.