Description
HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.
Published: 2026-07-16
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The missing access control flaw (CWE-284) in HCL DFXServer allows users to access certain API endpoints without authentication. Because these endpoints can be reached from any browser connected to the network, an attacker can invoke them and interact with the application without being verified. This can lead to unauthorized operations, potentially exposing sensitive information or altering configuration.

Affected Systems

HCL Software’s DFXServer application is impacted. The affected versions are not explicitly listed; all released versions of DFXServer appear vulnerable.

Risk and Exploitability

The flaw has a CVSS score of 6.3, indicating moderate severity. One of the endpoints is exposed to any network user through a standard browser. The EPSS score is less than 1%, indicating a very low but non-zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. However, the lack of authentication means that attackers with network access could abuse the endpoints quickly.

Generated by OpenCVE AI on July 31, 2026 at 02:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update HCL DFXServer to the latest release that resolves the access control issue.
  • Apply firewall or WAF rules to restrict the API endpoints to trusted IPs or networks.
  • Configure the application to require authentication for all API requests, ensuring proper authorization checks before performing actions.

Generated by OpenCVE AI on July 31, 2026 at 02:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware dfxserver
Vendors & Products Hclsoftware
Hclsoftware dfxserver

Thu, 16 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.
Title HCL DFXServer is affected by a Missing Access Control vulnerability
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}


Subscriptions

Hclsoftware Dfxserver
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-16T12:07:24.658Z

Reserved: 2026-04-01T16:32:01.022Z

Link: CVE-2026-35148

cve-icon Vulnrichment

Updated: 2026-07-16T12:07:19.843Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:15:06Z

Weaknesses