CVE-2026-35141: HCL DFXAnalytics is affected by a Login Replay Attack vulnerability
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every message, ensuring that messages exceeding a specific age threshold are automatically rejected by the recipient system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Modify the authentication workflow so every message includes a timestamp and the receiving system automatically rejects authentication messages that exceed the configured age threshold.
HCL DFXAnalytics authentication messaging timestamp inclusion and message age threshold enforcement = Implement timestamps on every authentication message and reject messages older than a specific age threshold
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35141?
The severity of CVE-2026-35141 is low, rated at 2.6.
How do I fix CVE-2026-35141?
To fix CVE-2026-35141, implement a mechanism to include timestamps in the authentication data to prevent replay attacks.
What type of attack is associated with CVE-2026-35141?
CVE-2026-35141 is associated with a Login Replay Attack vulnerability.
Which software is affected by CVE-2026-35141?
HCL DFXAnalytics is the software affected by CVE-2026-35141.
What can attackers do with CVE-2026-35141?
Attackers can intercept, delay, or fraudulently retransmit valid authentication data to gain unauthorized access using CVE-2026-35141.