Information Exposure Vulnerability in HCL iControl
CVE-2026-56568

3.7LOW

Key Information:

Vendor
CVE Published:
31 July 2026

What is CVE-2026-56568?

HCL iControl has a vulnerability that allows detailed server and API error messages to be displayed to users, instead of generic ones. This can inadvertently expose sensitive information, including internal endpoint names, request parameters, error codes, and authentication statuses. Such information can be leveraged by attackers for malicious activities, making it essential for users to apply appropriate measures to mitigate risks associated with this exposure.

Affected Version(s)

HCL iControl 4.3.0 and 4.4.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.