CVE-2026-66246: HCL iControl is affected by multiple security vulnerabilities
iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vector indicates that an attacker needs low privileges (PR:L). No user interaction is required, and exploitation can be performed over the network.
What could a successful attacker do?
A successful exploit could enable privilege escalation and unauthorized modification or deletion of sensitive application data. The reported impact includes high confidentiality, integrity, and availability effects.
Is a default iControl deployment affected?
The available information does not state whether the vulnerable access-control paths are enabled or reachable in a default configuration.