CVE-2026-56567
HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration fil
CVSS
5.1
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Jul 31, 2026 · Last modified: Jul 31, 2026 · CWE-15
Not enough EPSS history yet.
HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-464858.2 HIG22.8%
——7Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8.11dCVE-2026-447684.1 MED6.1%
——2SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and availability are not impacted.17dCVE-2026-04184.5 MED15.8%
——5Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network
to tamper with the system.8dCVE-2026-17848.8 HIG9.4%
——3The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.7hCVE-2019-257166.5 MED34.0%
——10Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet. Attackers can repeatedly send malformed network packets to disrupt patient monitoring until the device falls back to default configuration and loses network connectivity.9dCVE-2026-444177.5 HIG47.1%
——14The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.8d