CVE-2025-31952: Hcltech Dryice Iautomate

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.

Affected products

  • Hcltech Dryice Iautomate: version 6.5.1 only

Published 2025-07-24. Last modified 2026-06-17.