Low severity3.1NVD Advisory· Published Oct 1, 2026· Updated Oct 1, 2026
CVE-2026-66249
CVE-2026-66249
Description
iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.
Affected products
2Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.