CVE-2026-56609 MEDIUM

CVE-2026-56609: HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609).

Vendor Hcl Software
Product HCL iControl
Weakness CWE-327 · Broken crypto
Published August 3, 2026
Last update August 3, 2026

CVSS base score

4.8/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

What the vulnerability does

01Description

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission.

Key dates

02Disclosure timeline

August 3, 2026 CVE published
August 3, 2026 Record updated