CVE-2026-56608 PUBLISHED

HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609).

Assigner: HCL
Reserved: 22.06.2026 Published: 03.08.2026 Updated: 03.08.2026

HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 3.7

Product Status

Vendor HCL Software
Product HCL iControl
Versions Default: unaffected
  • Version v3.2.0 is affected

References

Problem Types

  • CWE-284 Improper Access Control CWE