Unrated severityNVD Advisory· Published Jul 16, 2026· Updated Jul 16, 2026
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability
CVE-2026-35140
Description
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.