Session Timeout Vulnerability in iControl by HCL Software
CVE-2026-66253
3.1LOW
What is CVE-2026-66253?
The iControl application by HCL Software is susceptible to a Session Timeout vulnerability. This issue arises when an active session remains unattended or abandoned, allowing an attacker to potentially exploit the session. If successful, the attacker could gain unauthorized access to the application and perform actions as if they were the original user, posing significant security risks.
Affected Version(s)
iControl v4.5.0
