Executive brief
HCL iControl, a business process monitoring and control platform, is affected by a security flaw where user sessions do not automatically expire after a period of inactivity. This could allow an unauthorized person to access an unattended workstation and perform actions using the previous user's active session. While the risk is rated as low, it could lead to unauthorized data access if physical or remote access to a logged-in device is obtained.
Technical details
HCL iControl v4.2.0 is vulnerable to insufficient session expiration (CWE-613). The web application fails to automatically invalidate or terminate a session after a period of inactivity, potentially allowing a session to remain active indefinitely. An attacker with low privileges or access to a user's environment could leverage an abandoned session to gain unauthorized access to the application's data. The vulnerability has a CVSS score of 3.1, reflecting a high complexity of exploit and the requirement for an existing authenticated session. HCL has acknowledged the issue in a security bulletin.
Affected products
- HCL Software iControl v4.2.0
Timeline
- 2026-06-17: advisory: HCL Software published the security bulletin.
- 2026-06-17: disclosed: CVE record published to NVD.