Description
iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session.
Published: 2026-10-01
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Data Exfiltration via Insecure CORS
Action: Patch
AI Analysis

Impact

HCL Software iControl contains an insecure Cross-Origin Resource Sharing (CORS) policy that permits a malicious website to send requests with credentials. An attacker could exploit this flaw to read data from the victim’s session and exfiltrate sensitive information. The weakness is an improper authorization control that allows cross‑origin credentialed access to protected resources, which could compromise confidentiality of data accessed by the victim’s authenticated session.

Affected Systems

The affected vendor is HCL Software, product iControl. No specific versions are listed in the available data, so all current installations of iControl should be considered potentially vulnerable until a vendor update is released.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The attack vector is inferred to be web‑based: a user must be logged in to iControl and visit a malicious site that can choose any origin allowed by the flawed CORS policy. The vulnerability allows data disclosure but does not provide privileged code execution or system compromise.

Generated by OpenCVE AI on October 1, 2026 at 16:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch or update to the latest iControl version as soon as it is available.
  • Configure the application’s CORS settings to disallow credentials for external origins, ensuring cross‑origin requests do not include authentication credentials.
  • Limit the allowed origins explicitly to trusted interfaces or domains, removing the "*" wildcard from the policy if present.
  • Monitor authentication traffic for unusual cross‑origin requests and use a WAF or CSP to block disallowed origins.

Generated by OpenCVE AI on October 1, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Title Insecure Cross‑Origin Resource Sharing (CORS) Policy Enabling Credentialed Requests
Weaknesses CWE-285

Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech icontrol
Vendors & Products Hcltech
Hcltech icontrol

Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Title Insecure Cross‑Origin Resource Sharing (CORS) Policy Enabling Credentialed Requests
Weaknesses CWE-285

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-942
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
Title HCL iControl is affected by multiple security vulnerabilities

Thu, 01 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Description iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session.
Title HCL iControl is affected by multiple security vulnerabilities
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hcltech Icontrol
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-10-01T13:49:51.789Z

Reserved: 2026-07-24T09:23:15.997Z

Link: CVE-2026-66247

cve-icon Vulnrichment

Updated: 2026-10-01T13:47:33.003Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T14:17:29.923

Modified: 2026-10-01T15:07:27.747

Link: CVE-2026-66247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:30:10Z

Weaknesses
  • CWE-942

    Permissive Cross-domain Security Policy with Untrusted Domains