Improper Error Handling Vulnerability in HCL Software iControl
CVE-2026-66248

3.1LOW

Key Information:

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-66248?

HCL Software's iControl is susceptible to an improper error handling vulnerability that may allow an unauthenticated attacker to exploit verbose error messages. By triggering these errors, attackers could gain insights into sensitive internal infrastructure, paving the way for advanced targeted attacks. Organizations using affected versions of iControl should prioritize reviewing their error handling mechanisms to safeguard sensitive information.

Affected Version(s)

iControl v4.5.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.