HCL Software iControl

5 known vulnerabilities in HCL Software iControl, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-66253 CVSS 3.1 low iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active…
  • CVE-2026-66249 CVSS 3.1 low iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over…
  • CVE-2026-66248 CVSS 3.1 low iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose…
  • CVE-2026-66247 CVSS 4.3 medium iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to…
  • CVE-2026-66246 CVSS 8.8 high iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or…