Junglewise Threat Intelligence

CVE-2026-35146: HCL DFXServer unencrypted communication via HTTP

CVE-2026-35146 · Severity: medium · CVSS 6.3 · Published 2026-07-16

Technologies: HCL Software DFXServer. Vendors: HCL Software.

Executive brief

HCL DFXServer allows users to connect using unencrypted HTTP connections rather than secure, encrypted channels. This flaw could allow an attacker to intercept network traffic, potentially exposing sensitive business data or login credentials as they travel across the network. This risk is particularly high for users accessing the server over public or untrusted networks.

Technical details

HCL DFXServer versions 2.5 and below are vulnerable to inadequate encryption strength (CWE-326) because the application permits communication over unencrypted HTTP. A remote attacker positioned on the network path between the user and the server can perform a man-in-the-middle (MitM) attack to intercept cleartext traffic. This can lead to the exposure of sensitive data, session tokens, or credentials. The vulnerability is exploitable over the network with no prior authentication required, though it typically requires user interaction (such as a user initiating a connection). HCL has addressed this in their security advisory KB0131782.

Affected products

  • HCL Software DFXServer 2.5 and below

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats