CVE-2026-66248: HCL iControl is affected by multiple security vulnerabilities
Published Oct 1, 2026
·Updated
iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose database and system errors, enabling the disclosure of sensitive internal infrastructure details used to plan advanced targeted attacks.
Affected Software
1 affected component
HCL iControl
Event History
Oct 1, 2026
CVE Published
via MITRE·01:26 PM
Data Sourced
via MITRE·01:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require authentication?
The provided data is inconsistent: the description says an unauthenticated attacker can trigger the errors, while the CVSS vector lists privileges required as low (PR:L). The available information does not resolve which access requirement applies.