Description
HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues.
Published: 2026-09-07
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unintended System Behavior
Action: Assess Impact
AI Analysis

Impact

This vulnerability is an instance of improper input validation that permits malicious or unexpected data to trigger unintended system behavior or other security issues. The description does not specify the type of data or exact output it can produce, but the weakness can potentially lead to data corruption or erratic application responses.

Affected Systems

The affected product is HCL Software’s MyXalytics. No specific version or subproduct information is available from the CNA records provided.

Risk and Exploitability

The CVSS score of 3.5 indicates a low severity issue. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Because the attack vector is not explicitly documented, it is inferred that the flaw could be exploited through input channels available to users or administrators, but the likelihood of exploitation appears low based on the available data.

Generated by OpenCVE AI on September 7, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and apply any HCL MyXalytics update or hotfix that addresses the improper input validation flaw.
  • Enforce stricter input validation or sanitization on any data that flows into MyXalytics to restrict unexpected or malicious content.
  • Enable and review logging for abnormal input patterns or errors that may indicate attempts to exploit the weakness.

Generated by OpenCVE AI on September 7, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech myxalytics
Vendors & Products Hcltech
Hcltech myxalytics

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues.
Title HCL MyXalytics is affected by multiple security vulnerabilities.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Hcltech Myxalytics
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-09-08T15:23:30.041Z

Reserved: 2025-06-18T14:00:44.549Z

Link: CVE-2025-52651

cve-icon Vulnrichment

Updated: 2026-09-08T15:23:18.756Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-07T11:17:19.503

Modified: 2026-09-08T16:17:49.917

Link: CVE-2025-52651

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:37:40Z

Weaknesses
  • CWE-20

    Improper Input Validation