ZeroHour

CVE-2026-35149

CVSS 3.1
8.2 high
EPSS
<1%p35
Published
()
Modified
Description

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.

Vendors
hcltech
Products
dfx server
Weakness
CWE-294
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.