Junglewise Threat Intelligence

CVE-2026-35143: HCL DFXAnalytics missing SameSite attribute in session cookies

CVE-2026-35143 · Severity: low · CVSS 3 · Published 2026-07-16

Technologies: HCL Software DFXAnalytics. Vendors: HCL Software.

Executive brief

HCL DFXAnalytics, a data analytics platform, contains a security flaw where session cookies are not properly configured to prevent unauthorized cross-site requests. If a logged-in user visits a malicious website, an attacker could potentially perform actions on the user's behalf within the DFXAnalytics application. This risk is primarily present if the application lacks other standard defenses like anti-forgery tokens.

Technical details

HCL DFXAnalytics fails to set the 'SameSite' attribute on session cookies generated during the authentication process. This omission allows the browser to send the session cookie during cross-site requests, creating a vulnerability to Cross-Site Request Forgery (CSRF). An attacker could exploit this by tricking an authenticated user into visiting a malicious site that triggers unauthorized requests to the DFXAnalytics application. The impact is mitigated if the application implements secondary defenses such as Anti-CSRF tokens. The vulnerability affects version 3.0 and below.

Affected products

  • HCL Software DFXAnalytics 3.0 and below

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats