Junglewise Threat Intelligence

CVE-2025-52606: HCL iControl weak input validation

CVE-2025-52606 · Severity: medium · CVSS 4.3 · Published 2026-06-04

Vendors: HCL.

Executive brief

HCL iControl, a business process monitoring and visibility platform, is affected by a security flaw where it fails to properly validate user-provided data. This could allow an authenticated user to submit unexpected information that the system does not correctly verify, potentially leading to minor data integrity issues or the generation of error messages containing sensitive technical details. While the risk is rated as medium, it highlights a gap in the application's security architecture regarding how it handles incoming requests.

Technical details

HCL iControl contains a weak input validation vulnerability (CWE-20) arising from the improper implementation of architectural security tactics. The application receives input expected to be of a specific type but fails to validate or incorrectly validates that the input matches that type. According to the associated CWE-209 classification, this may result in the generation of error messages containing sensitive information. The vulnerability is network-reachable and requires low-privileged authentication (PR:L) to exploit. Successful exploitation allows an attacker to impact system integrity (I:L) by submitting malformed data that is not properly filtered by the application logic.

Affected products

  • HCL iControl

Timeline

  • 2026-06-04: advisory: Initial advisory published by HCL Software
  • 2026-06-04: disclosed: CVE-2025-52606 published to the NVD dataset

References

Related threats