CVE-2026-35149

HIGH

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.

Title source: cna
STIX 2.1

Description

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.

Scores

CVSS v3 8.2
EPSS 0.0025
EPSS Percentile 16.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-294
Status published
Products (2)
HCL Software/DFXServer version 2.5 and below
hcltech/dfx_server < 2.5
Published Jul 16, 2026
Tracked Since Jul 16, 2026