CVE-2026-66248

iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose database and system errors, enabling the disclosure of sensitive internal infrastructure details used to plan advanced targeted attacks.

  • Published Oct 1, 2026
  • CVSS 3.1 low
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-66248 at the National Vulnerability Database