CVE-2026-35149
HIGHHCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.
Title source: cnaDescription
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.
References (1)
Core 1
Scores
CVSS v3
8.2
EPSS
0.0025
EPSS Percentile
16.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-294
Status
published
Products (2)
HCL Software/DFXServer
version 2.5 and below
hcltech/dfx_server
< 2.5
Published
Jul 16, 2026
Tracked Since
Jul 16, 2026