CVE-2026-56570
Received Received - Intake

Auto Complete Enabled in HCL iControl Exposes Sensitive Data

Vulnerability report for CVE-2026-56570, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: HCL Software

Description

HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcl icontrol *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HCL iControl has autocomplete enabled for sensitive fields like login forms. This allows browsers to store and suggest previously entered data such as usernames, email addresses, and account identifiers. Attackers in shared environments could exploit this to enumerate valid usernames through browser autofill suggestions.

Detection Guidance

This vulnerability involves autocomplete-enabled fields exposing sensitive information like usernames or email addresses. Check web application forms in HCL iControl for autocomplete attributes set to 'on' or missing 'off' values. Manually inspect login pages or use browser developer tools to review HTML form elements for autocomplete settings.

Impact Analysis

Attackers may gain access to valid usernames, email addresses, or account IDs if the system is used in shared environments. This could lead to targeted phishing attempts or unauthorized access attempts using exposed credentials.

Compliance Impact

This vulnerability may expose personal data such as usernames and email addresses, potentially violating GDPR's data protection principles. For HIPAA, unauthorized access to account identifiers could compromise protected health information if linked to user accounts.

Mitigation Strategies

Disable autocomplete for sensitive fields in HCL iControl login and user forms by setting autocomplete='off' in HTML forms. Update to the latest patched version of HCL iControl if available. Restrict access to shared environments where this vulnerability could be exploited.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56570. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart