CVE-2026-66249
LOW
NVD
CVSS Score
3.1
Severity
LOW
Published
Oct 01, 2026
Vendor
unknown
Description
iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.