CVE-2026-66249
3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Summary
iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCL Software | iControl | v4.5.0 | affected |
Weaknesses
- CWE-614: CWE-614 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.