CVE-2026-66247: Hcl Software Icontrol
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session.
Affected products
- Hcl Software Icontrol: version v4.5.0 only
Published 2026-10-01. Last modified 2026-10-01.