Auto Complete Vulnerability in HCL iControl Software
CVE-2026-56570

3.7LOW

Key Information:

Vendor
CVE Published:
31 July 2026

What is CVE-2026-56570?

HCL iControl is vulnerable to issues arising from auto complete features that expose sensitive user information. In shared environments, attackers can leverage browser suggestions to enumerate valid usernames, email addresses used for login, and account identifiers. This potential information leak may significantly heighten the risk of unauthorized access and exploitation, making it crucial for users to secure their implementation against such vulnerabilities.

Affected Version(s)

HCL iControl 4.3.0 and 4.4.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.