CVE-2026-35148: HCL DFXServer is affected by a Missing Access Control vulnerability
HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35148?
The severity of CVE-2026-35148 is medium with a score of 6.3.
How do I fix CVE-2026-35148?
To fix CVE-2026-35148, implement access control mechanisms to secure the exposed endpoints.
What type of vulnerability is CVE-2026-35148?
CVE-2026-35148 is a Missing Access Control vulnerability.
Who is affected by CVE-2026-35148?
HCL DFXServer users are affected by CVE-2026-35148 due to unauthorized access to certain endpoints.
What impact does CVE-2026-35148 have on HCL DFXServer?
CVE-2026-35148 allows any network user to invoke APIs without authentication, potentially leading to unauthorized actions within the application.