Three low-severity vulnerabilities, disclosed by HCL Software directly, affect MyXalytics — all CVSS 3.1 base 3.5 (low).
CVE-2025-52651: improper input validation
Per HCL’s own advisory, MyXalytics fails to adequately validate input, which may allow malicious or unexpected data to cause unintended system behavior or security issues.
CVE-2025-52652: content spoofing
Per HCL’s own advisory, the product may allow an attacker to manipulate displayed content so it appears to originate from a trusted source — a vector for phishing or data theft against users of the application.
CVE-2025-52657: potential denial of service via unbounded input
Per HCL’s own advisory, MyXalytics allows users to input data with no restriction on character count, which can impact system performance or availability.
Confidence
All three trace directly to HCL Software’s own vendor advisory (a single knowledge-base article covering all three), not a third-party researcher submission — confidence is high.
Why this matters
None of these three rises to the severity of the KEV-listed or high-CVSS findings covered elsewhere on this site, but they share a common root cause worth naming: insufficient input validation across multiple surfaces of the same product. Organizations running MyXalytics should apply HCL’s guidance for all three together, since they likely share a remediation path (stricter server-side input validation) even though each was assigned a separate CVE.
Frequently Asked Questions
What are CVE-2025-52651, 52652, and 52657? Three low-severity (CVSS 3.5) vulnerabilities in HCL MyXalytics: improper input validation, content spoofing, and a denial-of-service risk from unrestricted input length.
Where can I find the fix for these vulnerabilities? HCL Software’s own knowledge-base article, KB0132828, covers all three — consult it directly for patched versions.
Are these vulnerabilities being actively exploited? No evidence of active exploitation has been reported as of this writing; none are listed in CISA’s KEV catalog.
Data sourced from HCL Software’s own vendor advisory, aggregated September 2026. See more vulnerability intelligence.