SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-56586

LOW · CVSS 3.1 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

HCL IEM is vulnerable due to the absence of the X-Content-Type-Options header, which can expose users to SSL stripping and man-in-the-middle attacks, potentially allowing attackers to intercept sensitive data. Organizations utilizing HCL IEM should prioritize addressing this vulnerability to safeguard against these risks, despite the low severity rating.

CVE
CVE-2026-56586
Severity
LOW
CVSS
3.1
EPSS
0.12%

Original NVD Description

HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.

Related CVEs

Other vulnerabilities affecting the same vendor(s)