CVE-2026-35147 – HCL DFXServer
“When authentication checks fail, unauthorized access becomes far easier than intended.”
HCL Software has released updates for DFXServer to address two high-severity authentication vulnerabilities. The first vulnerability is a broken authentication flaw that allows unauthenticated attackers to access specific API endpoints and perform unauthorized actions because the application fails to verify a user’s authentication status. The second vulnerability is an authentication bypass flaw that allows attackers to manipulate server authentication responses to gain unauthorized access without valid credentials.
CVE-2026-35147 has a CVSS score of 8.2, High severity. CVE-2026-35149 has a CVSS score of 8.2, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with either vulnerability.
Key Details
- Affected Product
- Hcltech Dfx Server
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-639