Sensitive Data Exposure in HCL iControl - HCL Software
CVE-2026-56569

4MEDIUM

Key Information:

Vendor
CVE Published:
31 July 2026

What is CVE-2026-56569?

HCL iControl suffers from a sensitive data exposure vulnerability that allows unauthorized public access to internal configuration files. This flaw arises from inadequate hardening of the web server or application, potentially leading to the unintentional disclosure of critical system information to malicious actors. Proper configuration and robust security measures are essential to safeguard sensitive data.

Affected Version(s)

HCL iControl 4.3.0 and 4.4.0

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.