CVE-2026-35140: HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35140?
The severity of CVE-2026-35140 is classified as low with a score of 3.
How do I fix CVE-2026-35140?
To fix CVE-2026-35140, ensure that the 'secure' attribute is set on session cookies generated during authentication.
What vulnerability does CVE-2026-35140 represent?
CVE-2026-35140 represents a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability.
What risks are associated with CVE-2026-35140?
CVE-2026-35140 poses a risk of remote attackers intercepting network traffic and capturing sensitive cookie information.
Which software is affected by CVE-2026-35140?
CVE-2026-35140 affects HCL DFXAnalytics.