CVE-2026-56567 PUBLISHED

HCL iControl is affected by multiple security vulnerabilities.

Assigner: HCL
Reserved: 22.06.2026 Published: 31.07.2026 Updated: 31.07.2026

HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 5.1

Product Status

Vendor HCL Software
Product HCL iControl
Versions Default: unaffected
  • Version v4.4.0 and v4.3.0 is affected

References

Problem Types

  • CWE-15 External Control of System or Configuration Setting CWE