SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-35148

MEDIUM · CVSS 6.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

HCL DFXServer has a Missing Access Control vulnerability that allows unauthenticated network users to access certain APIs, enabling them to interact with the application without proper identity verification or authorization. This could lead to unauthorized data exposure or manipulation. Organizations using HCL DFXServer should prioritize addressing this vulnerability to safeguard against potential exploitation.

CVE
CVE-2026-35148
Severity
MEDIUM
CVSS
6.3
EPSS
0.17%

Original NVD Description

HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.

Related CVEs

Other vulnerabilities affecting the same vendor(s)