CVE-2026-66249
Received Received - Intake

Missing Secure Attribute in iControl Exposes Cookies to Interception

Vulnerability report for CVE-2026-66249, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: HCL Software

Description

iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcl icontrol *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-614 The Secure attribute for sensitive cookies in HTTPS sessions is not set.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Missing Secure Attribute issue in iControl. It allows attackers to intercept cookies sent over unencrypted HTTP connections, potentially stealing sensitive data like session identifiers.

Impact Analysis

An attacker could capture cookies transmitted over HTTP, leading to unauthorized access to user sessions or sensitive information. This may result in account hijacking or data theft.

Compliance Impact

This vulnerability could violate GDPR and HIPAA requirements for protecting sensitive data in transit. Organizations may face compliance penalties due to inadequate encryption of session cookies.

Mitigation Strategies

Enable HTTPS for all iControl communications to ensure cookies are transmitted over encrypted connections. Configure the secure attribute for session cookies to prevent interception over unencrypted HTTP.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66249. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart