CVE-2026-66247: HCL iControl is affected by multiple security vulnerabilities
iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Users with an active HCL iControl session who visit a malicious website are exposed, because the attack relies on cross-origin requests being sent with their credentials.
What does an attacker need to exploit this issue?
An attacker needs to lure a victim with an active iControl session to a malicious website. No user interaction beyond visiting that site is described, and the CVSS vector indicates low privileges are required.
What could an attacker obtain?
The described impact is access to and exfiltration of sensitive data available in the context of the victim's active session. The provided information does not describe an integrity or availability impact.