HomeHcltechCVE-2025-59870

CVE-2025-59870

HIGH
7.4CVSS
Published: 2026-01-16
Updated: 2026-01-23
AI Analysis

Description

HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
network
Complexity
high
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
none
Weaknesses
CWE-323

Metadata

Primary Vendor
HCLTECH
Published
1/16/2026
Last Modified
1/23/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

hcltech : myxalyticshcltech : myxalyticshcltech : myxalyticshcltech : myxalyticshcltech : myxalyticshcltech : myxalytics

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-59870 | HIGH Severity | CVEDatabase.com | CVEDatabase.com