Junglewise Threat Intelligence

CVE-2026-56570: HCL iControl sensitive information disclosure via enabled autocomplete

CVE-2026-56570 · Severity: low · CVSS 3.7 · Published 2026-07-31

Executive brief

HCL iControl, a business process monitoring and control platform, is affected by a configuration issue where login forms allow web browsers to store and suggest previously entered credentials. If the software is accessed from a shared computer or public terminal, an unauthorized person could potentially see valid usernames, email addresses, or account identifiers used by previous staff. This poses a risk of information disclosure and could assist in targeted social engineering or brute-force attacks.

Technical details

HCL iControl versions 4.3.0 and 4.4.0 fail to disable the HTML autocomplete attribute on sensitive input fields within the login interface. This leads to a violation of CWE-522 (Insufficiently Protected Credentials) as the browser may cache and subsequently suggest valid usernames, email addresses, and account identifiers. The attack vector is classified as network-based but requires the specific precondition of a shared environment where a subsequent user can view the cached entries of a previous user. An attacker can use this to enumerate valid accounts for further exploitation. HCL has addressed this in a security bulletin (KB0132395).

Affected products

  • HCL Software iControl 4.3.0, 4.4.0

Timeline

  • 2026-07-31: advisory: HCL Software published the security bulletin.
  • 2026-07-31: disclosed: CVE-2026-56570 was published to the NVD.

References