LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-35147

hcltech · dfx server

Published
CVSS8.2
Severityhigh
WeaknessCWE-639
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Description

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-35147

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-35147.