Description
HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
Published: 2026-07-31
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Sensitive Data Exposure flaw in HCL iControl that allows attackers to download internal configuration files because the web server or application does not properly harden paths. This can reveal credentials, network addresses, or other sensitive data that may be used to compromise the system. The weakness is identified as CWE-497.

Affected Systems

The affected product is HCL iControl from HCL Software. No specific version numbers are listed; the vulnerability applies to any deployments that have the misconfigured web server or application settings that expose configuration files.

Risk and Exploitability

The CVSS score of 4 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation at present. It is not listed in the CISA KEV catalog. The likely attack vector is via a web request that accesses an exposed configuration file; the attacker does not need authentication but must be able to reach the files. If the files contain credentials or system details, the impact could be confidentiality loss and potential subsequent lateral movement.

Generated by OpenCVE AI on August 2, 2026 at 04:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update or patch from HCL Software that addresses the configuration file exposure.
  • Configure the web server or application to restrict access to configuration directories, allowing only privileged users and disabling directory listings.
  • Ensure that error messages and debug information are not exposed in production by disabling verbose logging.
  • Perform a security audit of your web server configuration to detect any similar exposure paths not covered by the patch.

Generated by OpenCVE AI on August 2, 2026 at 04:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech icontrol
Vendors & Products Hcltech
Hcltech icontrol

Fri, 31 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
Title HCL iControl is affected by multiple security vulnerabilities.
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hcltech Icontrol
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-31T17:42:54.616Z

Reserved: 2026-06-22T13:39:42.053Z

Link: CVE-2026-56569

cve-icon Vulnrichment

Updated: 2026-07-31T17:42:49.915Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-31T16:17:07.523

Modified: 2026-08-05T14:31:52.807

Link: CVE-2026-56569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:32:43Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere