Executive brief
HCL DominoIQ, an AI-powered assistant for the Domino collaboration platform, contains a security flaw in its Retrieval-Augmented Generation (RAG) feature. This vulnerability allows users to bypass document-level security restrictions when asking the AI questions. As a result, an authorized user could potentially view sensitive corporate data that they are not officially permitted to access.
Technical details
A broken access control vulnerability (CWE-862) exists in the HCL DominoIQ Retrieval-Augmented Generation (RAG) component. The flaw occurs when the system fails to properly enforce document-level access control lists (ACLs) while retrieving context for AI-generated responses. An authenticated attacker with network access can craft queries that return information from restricted documents. The vulnerability has a CVSS base score of 6.5, reflecting high confidentiality impact but requiring at least low-level authentication. Users are advised to refer to HCL security bulletin KB0130932 for remediation steps.
Affected products
- HCL DominoIQ
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory: HCL published security bulletin KB0130932