Junglewise Threat Intelligence

CVE-2025-52652: HCL MyXalytics content spoofing

CVE-2025-52652 · Severity: low · CVSS 3.5 · Published 2026-09-07

Technologies: HCL MyXalytics. Vendors: HCL.

Executive brief

HCL MyXalytics is a business analytics platform used to monitor and analyze enterprise data. A content spoofing vulnerability allows attackers to manipulate the displayed content to appear as if it comes from a trusted source, creating a vector for phishing attacks or theft of sensitive business information.

Technical details

The vulnerability is a content spoofing flaw in HCL MyXalytics that permits an attacker to alter displayed content and make it appear as though it originates from a trusted source. This is typically achieved through insufficient output encoding, improper validation of user-controlled content, or failure to properly implement content security policies. The attack is network-accessible and does not require authentication or elevated privileges. A successful exploit could trick users into divulging credentials or sensitive data through convincing fake interface elements, though direct operational impact is limited.

Affected products

  • HCL MyXalytics

Timeline

  • 2026-09-07: disclosed

References

Related threats