Description
HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a trusted source, potentially leading to phishing or data theft.
Published: 2026-09-07
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Phishing and Data Theft through Content Spoofing
Action: Assess Impact
AI Analysis

Impact

HCL MyXalytics contains a content spoofing weakness that allows an attacker to alter displayed information so it appears to come from a trusted source. This manipulation can trick users into performing phishing attacks or unknowingly submitting sensitive data, thereby compromising confidentiality and integrity. The vulnerability is classified under CWE-451.

Affected Systems

The affected product is HCL Software’s MyXalytics. No specific version information is provided in the data, so the scope of the issue across releases is unknown.

Risk and Exploitability

The CVSS score of 3.5 indicates a low to moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires an attacker to influence the content that a user views, exploitation would typically depend on user interaction or the presence of a compromised content source.

Generated by OpenCVE AI on September 7, 2026 at 13:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review the HCL support article linked in the advisory to determine if a patch or configuration fix is available for MyXalytics.
  • Apply any vendor‑provided update or recommended setting change to prevent unauthorized content manipulation.
  • As an interim safeguard, implement strict validation of content source authenticity so that only trusted sources are rendered, reducing the risk of phishing or data theft.

Generated by OpenCVE AI on September 7, 2026 at 13:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech myxalytics
Vendors & Products Hcltech
Hcltech myxalytics

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a trusted source, potentially leading to phishing or data theft.
Title HCL MyXalytics is affected by multiple security vulnerabilities.
Weaknesses CWE-451
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Hcltech Myxalytics
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-09-08T15:22:56.744Z

Reserved: 2025-06-18T14:03:06.890Z

Link: CVE-2025-52652

cve-icon Vulnrichment

Updated: 2026-09-08T15:22:46.504Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-07T11:17:20.360

Modified: 2026-09-08T16:17:50.420

Link: CVE-2025-52652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:37:38Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information