{"id":"CVE-2026-66253","title":"iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ability to perform actions on behalf of …","summary":"iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ability to perform actions on behalf of …","severity":"low","cvss":3.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-613"],"vendor":"HCL Software","product":"iControl","affected":["iControl v4.5.0"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:07:27.747","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-66253","references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133940","label":"psirt@hcl.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-01T13:44:55.840Z","slug":"CVE-2026-66253","body":"## Overview\n\niControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ability to perform actions on behalf of the victim.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":17,"depthScoreParts":{"impact":17.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}