Executive brief
HCL Traveler is a mobile synchronization service that allows users to access email, calendar, and contacts from Apple devices. The vulnerability exists in how Traveler generates configuration profiles for Apple Mail, Calendar, and Contacts—it does not properly validate that the logon name and email address submitted by a user actually belong to that user's account. While an attacker can only target their own device with this flaw, the lack of validation creates a potential vector for account confusion or impersonation.
Technical details
This is an input validation and authorization flaw in HCL Traveler's Apple profile generation feature. When a user requests an Apple configuration profile for synchronizing Mail, Calendar, and Contacts, the service accepts and embeds the user-supplied logon name and email address into the profile without verifying they match the authenticated user's directory entry in Domino. Since these values are immutable in the generated profile and required for synchronization, an attacker could potentially embed incorrect or spoofed credentials. The vulnerability is network-reachable and requires authentication, but lacks sufficient output validation against the Domino directory. No patch status is currently indicated in the advisory.
Affected products
- HCL Traveler
Timeline
- 2026-08-26: disclosed