Description
iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.
Published: 2026-10-01
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability in HCL Software iControl arises from a missing 'Secure' attribute on session cookies. As a result, cookies containing session identifiers can be transmitted over plain HTTP connections. An attacker who can observe this traffic—such as through a network sniffing or a man‑in‑the‑middle attack—may capture these cookies and gain unauthorized access to user sessions, leading to exploitation of confidential information and potential impersonation of legitimate users.

Affected Systems

The affected product is HCL Software’s iControl. No specific version numbers are disclosed in the advisory; administrators should verify which releases impacted by reviewing the vendor’s update page referenced in the advisory.

Risk and Exploitability

The CVSS score of 3.1 indicates low overall severity, and the vulnerability is not listed in the CISA KEV catalog. However, the risk remains present because the exploitation path—capturing unencrypted cookies—can be performed by anyone with network visibility. No exploitable code execution is required, but session hijacking can grant extensive unauthorized access when an attacker successfully obtains a valid cookie.

Generated by OpenCVE AI on October 1, 2026 at 14:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the vendor‑provided fix for iControl.
  • Configure the application to set the Secure flag on all session cookies and enforce HTTPS.
  • Deploy network encryption or enforce TLS termination to prevent HTTP traffic.

Generated by OpenCVE AI on October 1, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech icontrol
Vendors & Products Hcltech
Hcltech icontrol

Thu, 01 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
Description iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.
Title HCL iControl is affected by a Missing Secure Attribute vulnerability
Weaknesses CWE-614
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-10-01T13:29:21.756Z

Reserved: 2026-07-24T09:23:15.997Z

Link: CVE-2026-66249

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T14:17:30.213

Modified: 2026-10-01T15:07:27.747

Link: CVE-2026-66249

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:34:57Z

Weaknesses
  • CWE-614

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute