High severity7.4NVD Advisory· Published Jan 16, 2026· Updated Jun 17, 2026
CVE-2025-59870
CVE-2025-59870
Description
HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
Affected products
8(expand)+ 1 more
- (no CPE)
- (no CPE)range: 6.2
cpe:2.3:a:hcltech:myxalytics:6.2:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:hcltech:myxalytics:6.2:*:*:*:*:*:*:*
- cpe:2.3:a:hcltech:myxalytics:6.3:*:*:*:*:*:*:*
- cpe:2.3:a:hcltech:myxalytics:6.4:*:*:*:*:*:*:*
- cpe:2.3:a:hcltech:myxalytics:6.5:*:*:*:*:*:*:*
- cpe:2.3:a:hcltech:myxalytics:6.6:*:*:*:*:*:*:*
- cpe:2.3:a:hcltech:myxalytics:6.7:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- support.hcl-software.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.