CVE-2026-66247 PUBLISHED

Assigner: HCL
Reserved: 24.07.2026 Published: 01.10.2026 Updated: 01.10.2026

iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor HCL Software
Product iControl
Versions Default: unaffected
  • Version v4.5.0 is affected

References