CVE-2026-56586
Received
Received - Intake
X-Content-Type-Options Header Missing in HCL IEM
Vulnerability report for CVE-2026-56586, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-21
Last updated on: 2026-07-21
Assigner: HCL Software
Description
Description
HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hcl | iem | * |
| hcl | intelliops_event_management | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-16 | Configuration |