CVE-2026-35146

HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.

Scoring

Severity
MEDIUM
CVSS base score
6.3
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
EPSS probability
0.19%
CWE
CWE-326
Published
2026-07-16
Last modified
2026-07-16

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs