Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Cross‑Origin Resource Sharing (CORS) Policy Enabling Credentialed Requests | |
| Weaknesses | CWE-285 |
Thu, 01 Oct 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech icontrol |
|
| Vendors & Products |
Hcltech
Hcltech icontrol |
Thu, 01 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Cross‑Origin Resource Sharing (CORS) Policy Enabling Credentialed Requests | |
| Weaknesses | CWE-285 |
Thu, 01 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-942 | |
| Metrics |
ssvc
|
Thu, 01 Oct 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | HCL iControl is affected by multiple security vulnerabilities |
Thu, 01 Oct 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session. | |
| Title | HCL iControl is affected by multiple security vulnerabilities | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-10-01T13:49:51.789Z
Reserved: 2026-07-24T09:23:15.997Z
Link: CVE-2026-66247
Updated: 2026-10-01T13:47:33.003Z
Status : Deferred
Published: 2026-10-01T14:17:29.923
Modified: 2026-10-01T15:07:27.747
Link: CVE-2026-66247
No data.
OpenCVE Enrichment
Updated: 2026-10-01T16:30:10Z