CVE-2026-35141EPSS p23.9%

CVE-2026-35141CVE-2026-35141

hcltech / dfxanalytics

Description

HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every message, ensuring that messages exceeding a specific age threshold are automatically rejected by the recipient system.

Scoring

CVSS 2.6 ()
VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N
EPSS0.33% probability of exploitation · percentile 23.9% · 2026-10-05T12:00:23Z
Last modified2026-07-17
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.