Session Timeout Vulnerability in iControl by HCL Software
CVE-2026-66253

3.1LOW

Key Information:

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-66253?

The iControl application by HCL Software is susceptible to a Session Timeout vulnerability. This issue arises when an active session remains unattended or abandoned, allowing an attacker to potentially exploit the session. If successful, the attacker could gain unauthorized access to the application and perform actions as if they were the original user, posing significant security risks.

Affected Version(s)

iControl v4.5.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.