CVE-2026-66249

iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.

  • Published Oct 1, 2026
  • CVSS 3.1 low
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-66249 at the National Vulnerability Database