CVE-2026-56569 PUBLISHED

HCL iControl is affected by multiple security vulnerabilities.

Assigner: HCL
Reserved: 22.06.2026 Published: 31.07.2026 Updated: 31.07.2026

HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4

Product Status

Vendor HCL Software
Product HCL iControl
Versions Default: unaffected
  • Version 4.3.0 and 4.4.0 is affected

References

Problem Types

  • CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere CWE