Description
HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
Published: 2026-07-31
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from a misconfiguration in HCL iControl v4.3.0 that permits publicly accessible internal configuration files. An attacker able to request these files can gain insight into system internals, potentially including credentials, network topology, and other sensitive settings. The impact is primarily a breach of confidentiality, with no direct evidence of code execution or denial of service.

Affected Systems

HCL Software’s HCL iControl, specifically version 4.3.0, is affected.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate risk, while the EPSS score of <1% reflects a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, and no exploit has been reported. Likely exploitation would involve a remote attacker issuing HTTP requests to the web server, but no critical privileges or credentials are required beyond network access to the exposed endpoint.

Generated by OpenCVE AI on August 2, 2026 at 04:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review the HCL advisory for any available patch or firmware update and apply it immediately.
  • Configure the web server to deny access to internal configuration directories and disable directory listings.
  • Ensure that file permissions on configuration files restrict web server access to only the necessary service accounts.

Generated by OpenCVE AI on August 2, 2026 at 04:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech icontrol
Vendors & Products Hcltech
Hcltech icontrol

Fri, 31 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
Title HCL iControl is affected by multiple security vulnerabilities.
Weaknesses CWE-15
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Hcltech Icontrol
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-31T17:46:04.546Z

Reserved: 2026-06-22T13:39:42.053Z

Link: CVE-2026-56567

cve-icon Vulnrichment

Updated: 2026-07-31T17:45:56.800Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-31T16:17:07.290

Modified: 2026-08-06T14:44:44.243

Link: CVE-2026-56567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:32:46Z

Weaknesses
  • CWE-15

    External Control of System or Configuration Setting