CVE-2025-59870

EUVD-2026-2950
HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
HCLCNA
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
Affected Products (NVD)
VendorProductVersion
hcltechmyxalytics
6.2
hcltechmyxalytics
6.3
hcltechmyxalytics
6.4
hcltechmyxalytics
6.5
hcltechmyxalytics
6.6
hcltechmyxalytics
6.7
𝑥
= Vulnerable software versions