CVE-2026-35147 – HCL DFXServer

CVSS 8.2 IMPORTANT High with EoP or RCE – Expedited Deployment

“When authentication checks fail, unauthorized access becomes far easier than intended.”

HCL Software has released updates for DFXServer to address two high-severity authentication vulnerabilities. The first vulnerability is a broken authentication flaw that allows unauthenticated attackers to access specific API endpoints and perform unauthorized actions because the application fails to verify a user’s authentication status. The second vulnerability is an authentication bypass flaw that allows attackers to manipulate server authentication responses to gain unauthorized access without valid credentials.

CVE-2026-35147 has a CVSS score of 8.2, High severity. CVE-2026-35149 has a CVSS score of 8.2, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with either vulnerability.

Key Details

Affected Product
Hcltech Dfx Server
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-639
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.