Description
HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions.
Published: 2026-07-31
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves an autocomplete-enabled flaw in HCL iControl that causes the browser to reveal sensitive information such as valid usernames, email addresses used for logon, and account identifiers. This weakness can allow an attacker to learn credential-related data that were intended to be private, constituting an information‑disclosure weakness (CWE‑522).

Affected Systems

Products affected are the HCL iControl web interface from HCL Software. No specific product versions are listed in the data, so all releases of HCL iControl remain potentially vulnerable until a vendor‑supplied fix is applied.

Risk and Exploitability

The CVSS base score is 3.7, indicating a low severity impact. The EPSS score is less than 1 %, suggesting that exploitation across the wild is unlikely. It is not identified in the CISA KEV catalog. The attack vector is inferred to be a local or shared‑environment attack; if an attacker can view the browser’s autocomplete suggestions, they can enumerate valid usernames. No explicit prerequisites are documented, but the vulnerability relies on the browser’s ability to present stored login data to the user.

Generated by OpenCVE AI on August 2, 2026 at 04:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable the autocomplete attribute for username and password fields in the HCL iControl login page
  • Configure secure browsing practices so that administrators do not log in from shared or public devices
  • Obtain and install the vendor‑supplied patch when it becomes available

Generated by OpenCVE AI on August 2, 2026 at 04:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech icontrol
Vendors & Products Hcltech
Hcltech icontrol

Fri, 31 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions.
Title HCL iControl is affected by multiple security vulnerabilities.
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hcltech Icontrol
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-31T17:42:23.156Z

Reserved: 2026-06-22T13:39:42.054Z

Link: CVE-2026-56570

cve-icon Vulnrichment

Updated: 2026-07-31T17:42:17.799Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-31T16:17:07.637

Modified: 2026-08-05T14:32:31.033

Link: CVE-2026-56570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:32:41Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials