Retour à la veille

CVE-2026-66249

Publié : 1 octobre 2026
Modifié : 1 octobre 2026
Lien officiel NVD
Score CVSS
3.1
LOW

Description détaillée

iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Références et Patchs