Missing Secure Attribute Vulnerability in HCL iControl
CVE-2026-66249
3.1LOW
What is CVE-2026-66249?
The iControl product by HCL Technologies is vulnerable due to a Missing Secure Attribute, allowing attackers to potentially intercept cookies over unencrypted HTTP connections. This vulnerability can lead to the unauthorized extraction of sensitive data, including session identifiers, which may be exploited for malicious purposes. Implementing secure attributes for cookies is crucial to ensure data integrity and confidentiality.
Affected Version(s)
iControl v4.5.0
