CVE-2026-56608
Analyzed Analyzed - Analysis Complete

Missing Access Control in HCL iControl

Vulnerability report for CVE-2026-56608, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-05

Assigner: HCL Software

Description

HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-05
Generated
2026-08-24
AI Q&A
2026-08-03
EPSS Evaluated
2026-08-22
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcltech icontrol 3.2.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HCL iControl has a Missing Access Control vulnerability where the application does not enforce proper granular access controls. This allows users to access or view administrator-level functionalities without the required authorization.

Impact Analysis

This vulnerability could allow unauthorized users to perform actions or view sensitive data that should only be accessible to administrators. The impact is limited as the CVSS score is low (3.7), indicating a lower risk of exploitation.

Compliance Impact

This vulnerability could potentially impact compliance with standards like GDPR and HIPAA by allowing unauthorized access to sensitive administrative functions. Missing access controls may lead to unauthorized data exposure or modification, violating confidentiality and integrity requirements in these regulations.

Mitigation Strategies

Apply vendor patches or updates from HCL for iControl to enforce proper access controls. Review and restrict user permissions to prevent unauthorized access to administrator-level functionalities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56608. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart