CVE-2026-35149

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:dfx_server:*:*:*:*:*:*:*:*

History

21 Jul 2026, 20:16

Type Values Removed Values Added
CPE cpe:2.3:a:hcltech:dfx_server:*:*:*:*:*:*:*:*
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131782 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131782 - Vendor Advisory
First Time Hcltech
Hcltech dfx Server

16 Jul 2026, 12:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-16 12:17

Updated : 2026-07-21 20:16


NVD link : CVE-2026-35149

Mitre link : CVE-2026-35149

CVE.ORG link : CVE-2026-35149


JSON object : View

Products Affected

hcltech

  • dfx_server
CWE
CWE-294

Authentication Bypass by Capture-replay