CVE-2026-66249: HCL iControl is affected by a Missing Secure Attribute vulnerability
Published Oct 1, 2026
·Updated
iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.
Affected Software
1 affected component
HCL iControl
Event History
Oct 1, 2026
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What conditions are required for exploitation?
An attacker needs the ability to intercept cookies sent over an unencrypted HTTP connection. The attacker would also need at least low-level privileges, and exploitation is rated as high complexity.
2
What information could be exposed if exploitation succeeds?
Sensitive cookie contents may be extracted, including session identifiers. The reported impact is limited to confidentiality; no integrity or availability impact is identified.