---
id: CVE-2026-66253
title: >-
  iControl is affected by a Session Timeout vulnerability, which could allow an
  attacker to exploit an unattended or abandoned active session, enabling
  unauthorized access to the application and the ability to perform actions on
  behalf of …
summary: >-
  iControl is affected by a Session Timeout vulnerability, which could allow an
  attacker to exploit an unattended or abandoned active session, enabling
  unauthorized access to the application and the ability to perform actions on
  behalf of …
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-613
vendor: HCL Software
product: iControl
affected:
  - iControl v4.5.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:07:27.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66253'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133940
    label: psirt@hcl.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T13:44:55.840Z'
---

## Overview

iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ability to perform actions on behalf of the victim.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
