CVE-2026-35143: HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability.
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF tokens, are not implemented.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35143?
The severity of CVE-2026-35143 is rated low with a score of 3.
What vulnerability does CVE-2026-35143 address?
CVE-2026-35143 addresses a Missing SameSite Attribute vulnerability in HCL DFXAnalytics.
How can CVE-2026-35143 be fixed?
CVE-2026-35143 can be fixed by setting the SameSite attribute on session cookies during authentication.
What security risk is associated with CVE-2026-35143?
CVE-2026-35143 poses a risk of Cross-Site Request Forgery (CSRF) attacks due to the missing SameSite attribute.
Which software is affected by CVE-2026-35143?
HCL DFXAnalytics is the software affected by CVE-2026-35143.