HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk
Metrics
Affected Vendors & Products
References
History
Fri, 23 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hcltech:myxalytics:6.2:*:*:*:*:*:*:* cpe:2.3:a:hcltech:myxalytics:6.3:*:*:*:*:*:*:* cpe:2.3:a:hcltech:myxalytics:6.4:*:*:*:*:*:*:* cpe:2.3:a:hcltech:myxalytics:6.5:*:*:*:*:*:*:* cpe:2.3:a:hcltech:myxalytics:6.6:*:*:*:*:*:*:* cpe:2.3:a:hcltech:myxalytics:6.7:*:*:*:*:*:*:* |
Wed, 21 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL MyXalytics v6.7 is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk | HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk |
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech myxalytics |
|
| Vendors & Products |
Hcltech
Hcltech myxalytics |
Fri, 16 Jan 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-323 | |
| Metrics |
ssvc
|
Fri, 16 Jan 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL MyXalytics v6.7 is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk | |
| Title | Improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published: 2026-01-16T10:12:01.499Z
Updated: 2026-01-21T11:12:41.559Z
Reserved: 2025-09-22T15:00:11.103Z
Link: CVE-2025-59870
Updated: 2026-01-16T12:12:34.680Z
Status : Analyzed
Published: 2026-01-16T11:16:02.660
Modified: 2026-01-23T17:05:07.123
Link: CVE-2025-59870
No data.