Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Cross‑Origin Resource Sharing (CORS) Policy Enabling Credentialed Requests | |
| Weaknesses | CWE-285 |
Thu, 01 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-942 | |
| Metrics |
ssvc
|
Thu, 01 Oct 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | HCL iControl is affected by multiple security vulnerabilities |
Thu, 01 Oct 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session. | |
| Title | HCL iControl is affected by multiple security vulnerabilities | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-10-01T13:49:51.789Z
Reserved: 2026-07-24T09:23:15.997Z
Link: CVE-2026-66247
Updated: 2026-10-01T13:47:33.003Z
Status : Received
Published: 2026-10-01T14:17:29.923
Modified: 2026-10-01T14:17:29.923
Link: CVE-2026-66247
No data.
OpenCVE Enrichment
Updated: 2026-10-01T14:30:08Z