CVE-2026-35145 dfxanalytics vulnerability
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses.
Browse Web Application security risksQuick answer
hcltech dfxanalytics should be reviewed and updated if it matches the affected versions. The recommended fix is to apply the vendor-supported patched version or the mitigation steps below, then retest the public website with Fixnx.
Who is affected
Affected versions
- Review vendor advisory for affected versions.
Fixed versions
- Apply the latest vendor-supported patched version.
How to fix it
CVE-2026-35145 affects HCL DFXAnalytics. The issue can weaken browser or session protection. Apply the vendor fix and harden the web and session settings around DFXAnalytics.
- Apply the HCL DFXAnalytics update or vendor mitigation that fixes CVE-2026-35145.
- Restrict access to the DFXAnalytics dashboard to trusted users and networks.
- Disable debug output and make sure errors do not expose file paths, IP addresses, or internal details.
- Harden transport and session settings: use TLS 1.2 or 1.3, HSTS, Secure cookies, SameSite cookies, and anti-CSRF controls where relevant.
- Review application, proxy, and authentication logs for signs of crashes, replay attempts, account changes, or suspicious response manipulation.
Scan now. Google sign-in is only needed to unlock fix guidance.
Verify the fix
- Confirm DFXAnalytics is on a fixed vendor version or has the vendor mitigation applied.
- Run a fresh scan and confirm this CVE no longer appears.
- Check response headers, TLS settings, and error pages from a browser or scanner.
Related categories
Related security risks
More published guidance from the same primary category.
Trusted references
FAQ
What is affected by CVE-2026-35145?
hcltech dfxanalytics should be checked against the vendor advisory and trusted references linked on this page.
What should I fix first?
Start with internet-facing sites, admin panels, login flows, plugins, themes, modules, packages, and systems that process user-controlled input or sensitive data.
How do I confirm the fix worked?
Apply the patched version or mitigation, clear caches where relevant, retest the affected workflow, and run a new Fixnx scan to verify public website exposure signals.
How are Fixnx security risk categories chosen?
Fixnx keeps one canonical risk page and assigns only broad, relevant categories such as ecosystem, technology area, or vulnerability class.
