Loading market data...
← Back to CVE feed

CVE-2026-66247

MEDIUM CVSS 4.3 View on NVD ↗

Description

iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Published: Oct 01, 2026 14:17 UTC Modified: Oct 01, 2026 15:07 UTC