CVE-2026-66247: Hcl Software Icontrol

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session.

Affected products

Published 2026-10-01. Last modified 2026-10-01.