CVE Vulnerabilities

CVE-2025-59870

Reusing a Nonce, Key Pair in Encryption

Published: Jan 16, 2026 | Modified: Jan 23, 2026
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk

Weakness

Nonces should be used for the present occasion and only once.

Affected Software

NameVendorStart VersionEnd Version
MyxalyticsHcltech6.2 (including)6.2 (including)
MyxalyticsHcltech6.3 (including)6.3 (including)
MyxalyticsHcltech6.4 (including)6.4 (including)
MyxalyticsHcltech6.5 (including)6.5 (including)
MyxalyticsHcltech6.6 (including)6.6 (including)
MyxalyticsHcltech6.7 (including)6.7 (including)

Potential Mitigations

References