Junglewise Threat Intelligence

CVE-2026-35149: HCL DFXServer authentication bypass via response manipulation

CVE-2026-35149 · Severity: high · CVSS 8.2 · Published 2026-07-16

Technologies: HCL Software DFXServer. Vendors: HCL Software.

Executive brief

HCL DFXServer is vulnerable to a security flaw that allows unauthorized individuals to bypass login requirements. By intercepting and modifying the server's responses during the login process, an attacker can gain full access to the application without providing valid credentials. This could lead to the exposure of sensitive data and unauthorized control over the server's functions.

Technical details

HCL DFXServer versions 2.5 and below are vulnerable to an authentication bypass (CWE-294) via server response manipulation. The vulnerability exists because the application incorrectly trusts or fails to properly validate authentication responses that have been intercepted and altered by an attacker. A remote, unauthenticated attacker can exploit this by manipulating the server's response to indicate a successful login, thereby gaining unauthorized access to the application. The attack is carried out over the network with low complexity and requires no user interaction. HCL Software has acknowledged the issue in security bulletin KB0131782.

Affected products

  • HCL Software DFXServer 2.5 and below

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats