SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-35147

HIGH · CVSS 8.2 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

HCL DFXServer is vulnerable due to a broken authentication flaw that permits unauthenticated access to certain API endpoints, enabling attackers to execute unauthorized actions without proper credentials. This high-severity vulnerability poses significant risks to data integrity and system security. Organizations utilizing HCL DFXServer should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-35147
Severity
HIGH
CVSS
8.2
EPSS
0.27%

Original NVD Description

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials.

Related CVEs

Other vulnerabilities affecting the same vendor(s)