Junglewise Threat Intelligence

CVE-2026-21836: HCL DominoIQ broken access control in RAG feature

CVE-2026-21836 · Severity: medium · CVSS 6.5 · Published 2026-05-20

Vendors: HCL.

Executive brief

HCL DominoIQ, an AI-powered assistant for the Domino collaboration platform, contains a security flaw in its Retrieval-Augmented Generation (RAG) feature. This vulnerability allows users to bypass document-level security restrictions when asking the AI questions. As a result, an authorized user could potentially view sensitive corporate data that they are not officially permitted to access.

Technical details

A broken access control vulnerability (CWE-862) exists in the HCL DominoIQ Retrieval-Augmented Generation (RAG) component. The flaw occurs when the system fails to properly enforce document-level access control lists (ACLs) while retrieving context for AI-generated responses. An authenticated attacker with network access can craft queries that return information from restricted documents. The vulnerability has a CVSS base score of 6.5, reflecting high confidentiality impact but requiring at least low-level authentication. Users are advised to refer to HCL security bulletin KB0130932 for remediation steps.

Affected products

  • HCL DominoIQ

Timeline

  • 2026-05-20: disclosed
  • 2026-05-20: advisory: HCL published security bulletin KB0130932

References