Disclosure summary
iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ability to perform actions on behalf of the victim.
Source-reported weakness categories
CWE-613
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-66253
Open original source · Updated Oct 01, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
PUBLISHED 2026-10-01T10:17:30-04:00
MODIFIED 2026-10-01T11:07:27-04:00
INGESTED 2026-10-06T11:45:14-04:00