---
id: CVE-2026-66249
title: >-
  iControl is affected by a Missing Secure Attribute vulnerability, which could
  allow an attacker to intercept cookies transmitted over unencrypted HTTP
  connections, enabling the unauthorized extraction of sensitive information
  such as ses…
summary: >-
  iControl is affected by a Missing Secure Attribute vulnerability, which could
  allow an attacker to intercept cookies transmitted over unencrypted HTTP
  connections, enabling the unauthorized extraction of sensitive information
  such as ses…
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-614
vendor: HCL Software
product: iControl
affected:
  - iControl v4.5.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:07:27.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66249'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133940
    label: psirt@hcl.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T13:44:55.837Z'
---

## Overview

iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
