CVE-2026-35149 HIGH

CVE-2026-35149: HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.

Vendor Hcl Software
Product DFXServer
Weakness CWE-294
Published July 16, 2026
Last update July 16, 2026

CVSS base score

8.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

What the vulnerability does

01Description

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.

Key dates

02Disclosure timeline

July 16, 2026 CVE published