---
id: CVE-2026-66246
title: >-
  iControl is affected by a Broken Access Control vulnerability, which could
  allow an attacker to exploit missing authentication checks or insecure direct
  object references (IDOR), enabling privilege escalation and the unauthorized
  modific…
summary: >-
  iControl is affected by a Broken Access Control vulnerability, which could
  allow an attacker to exploit missing authentication checks or insecure direct
  object references (IDOR), enabling privilege escalation and the unauthorized
  modific…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-250
vendor: HCL Software
product: iControl
affected:
  - iControl v4.5.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:07:27.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66246'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133940
    label: psirt@hcl.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-01T13:51:10.073733Z'
ingestedAt: '2026-10-01T13:44:55.839Z'
---

## Overview

iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
