CVE-2026-66247
iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session.
- Published Oct 1, 2026
- CVSS 4.3 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)