CVE-2026-56608: HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609).
Published Aug 3, 2026
·Updated
HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.
Affected Software
1 affected component
HCL iControl
Event History
Aug 3, 2026
CVE Published
via MITRE·11:25 AM
Data Sourced
via MITRE·11:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-56608?
The severity of CVE-2026-56608 is classified as low with a score of 3.7.
2
What type of vulnerability is CVE-2026-56608?
CVE-2026-56608 is a Missing Access Control vulnerability.
3
How does CVE-2026-56608 affect HCL iControl?
CVE-2026-56608 allows unauthorized users to access administrator-level functionalities due to insufficient access controls.
4
Is there a fix available for CVE-2026-56608?
Yes, a fix is recommended in the software updates from HCL for CVE-2026-56608.
5
What is the impact of CVE-2026-56608 on data security in HCL iControl?
CVE-2026-56608 can lead to unauthorized data access, compromising the security of sensitive administrator functionalities.