Junglewise Threat Intelligence

CVE-2026-56567: HCL iControl configuration file exposure via security misconfiguration

CVE-2026-56567 · Severity: medium · CVSS 5.1 · Published 2026-07-31

Executive brief

HCL iControl, a monitoring and management solution, is affected by a security misconfiguration that exposes internal configuration files. This could allow an unauthorized person with local access to the system to view sensitive settings or modify configuration parameters. Such exposure could lead to unauthorized changes in how the application operates or provide a foothold for further attacks.

Technical details

HCL iControl versions 4.3.0 and 4.4.0 suffer from a security misconfiguration (CWE-15) where internal configuration files are publicly exposed. The root cause is attributed to improper hardening of the web server or application environment. An attacker with local access can exploit this to read or potentially modify system and configuration settings without requiring elevated privileges or user interaction. This vulnerability is tracked as CVE-2026-56567 and has a CVSS base score of 5.1. Users are advised to refer to HCL Software advisory KB0132395 for remediation steps.

Affected products

  • HCL Software iControl v4.3.0, v4.4.0

Timeline

  • 2026-07-31: disclosed
  • 2026-07-31: advisory

References