CVE-2026-66253: HCL iControl is affected by a Session Timeout vulnerability
Published Oct 1, 2026
·Updated
iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ability to perform actions on behalf of the victim.
Affected Software
1 affected component
HCL iControl
Event History
Oct 1, 2026
CVE Published
via MITRE·01:30 PM
Data Sourced
via MITRE·01:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What conditions must exist for an attacker to exploit this issue?
An attacker needs access to an unattended or abandoned active iControl session. The vulnerability requires low privileges and has high attack complexity, according to the supplied vector.
2
What could an attacker do using an exploited session?
An attacker could obtain unauthorized access to the application and perform actions on behalf of the victim. The stated impact is limited to confidentiality; no integrity or availability impact is identified.