CVE-2026-56453

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:dfxanalytics:*:*:*:*:*:*:*:*

History

17 Jul 2026, 19:09

Type Values Removed Values Added
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787 - Vendor Advisory
First Time Hcltech dfxanalytics
Hcltech
CPE cpe:2.3:a:hcltech:dfxanalytics:*:*:*:*:*:*:*:*

16 Jul 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-16 14:16

Updated : 2026-07-17 19:09


NVD link : CVE-2026-56453

Mitre link : CVE-2026-56453

CVE.ORG link : CVE-2026-56453


JSON object : View

Products Affected

hcltech

  • dfxanalytics
CWE
CWE-294

Authentication Bypass by Capture-replay