Description
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.
Published: 2026-07-16
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL DFXServer exposes an authentication bypass vulnerability that allows an adversary without valid credentials to gain access by intercepting and modifying the server’s authentication responses. The flaw is a process and input‑related weakness classified as CWE‑294, enabling a malicious user to alter response data so the server accepts unauthorized tokens or credentials.

Affected Systems

The vulnerability affects HCL Software’s DFXServer product. No version‑specific information is supplied, implying that all currently deployed releases could be susceptible until the vendor releases an official fix.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. The EPSS score is below 1 %, suggesting a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves intercepting traffic between a client and the DFXServer—such as through man‑in‑the‑middle techniques or unauthorized proxies—to modify authentication responses. An attacker needs network access to the communication path but does not require elevated privileges on the server to exploit the flaw.

Generated by OpenCVE AI on July 31, 2026 at 02:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HCL Software patch that resolves the authentication bypass in DFXServer.
  • Enforce TLS to encrypt all traffic, preventing attackers from tampering with authentication messages.
  • Restrict client connections to trusted hosts and disable unauthorized proxy or interception mechanisms until the patch is installed.
  • Monitor authentication logs for anomalous access attempts and investigate any unauthorized activity promptly.

Generated by OpenCVE AI on July 31, 2026 at 02:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware dfxserver
Vendors & Products Hclsoftware
Hclsoftware dfxserver

Thu, 16 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.
Title HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.
Weaknesses CWE-294
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Hclsoftware Dfxserver
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-16T12:06:39.721Z

Reserved: 2026-04-01T16:32:01.022Z

Link: CVE-2026-35149

cve-icon Vulnrichment

Updated: 2026-07-16T12:06:32.857Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:15:06Z

Weaknesses
  • CWE-294

    Authentication Bypass by Capture-replay