SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-35140

LOW · CVSS 3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

HCL DFXAnalytics is vulnerable due to the absence of the "secure" attribute on session cookies generated during authentication, potentially exposing sensitive data to interception by remote attackers. This flaw could allow attackers to capture session tokens and credentials transmitted over unencrypted channels. Organizations using HCL DFXAnalytics should prioritize addressing this vulnerability to mitigate the risk of credential theft and session hijacking.

CVE
CVE-2026-35140
Severity
LOW
CVSS
3
EPSS
0.16%

Original NVD Description

HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels.

Related CVEs

Other vulnerabilities affecting the same vendor(s)