SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-56568

LOW · CVSS 3.7 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

HCL iControl is vulnerable due to its exposure of verbose client-side API error messages, which reveal sensitive information such as internal endpoint names, request parameters, error codes, and authentication status. This information leakage could aid attackers in crafting targeted exploits against the application. Organizations using HCL iControl should prioritize addressing this vulnerability to mitigate potential risks associated with information exposure.

CVE
CVE-2026-56568
Severity
LOW
CVSS
3.7
EPSS
0.20%

Original NVD Description

HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status

Related CVEs

Other vulnerabilities affecting the same vendor(s)