CVE-2026-66249: Hcl Software Icontrol
Low severity, CVSS 3.1. EPSS: 0.1% chance of exploitation in the next 30 days.
iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.
Affected products
- Hcl Software Icontrol: version v4.5.0 only
Published 2026-10-01. Last modified 2026-10-01.