Executive brief
HCL MyXalytics is a business analytics platform used to monitor and analyze enterprise data. A content spoofing vulnerability allows attackers to manipulate the displayed content to appear as if it comes from a trusted source, creating a vector for phishing attacks or theft of sensitive business information.
Technical details
The vulnerability is a content spoofing flaw in HCL MyXalytics that permits an attacker to alter displayed content and make it appear as though it originates from a trusted source. This is typically achieved through insufficient output encoding, improper validation of user-controlled content, or failure to properly implement content security policies. The attack is network-accessible and does not require authentication or elevated privileges. A successful exploit could trick users into divulging credentials or sensitive data through convincing fake interface elements, though direct operational impact is limited.
Affected products
- HCL MyXalytics
Timeline
- 2026-09-07: disclosed