Junglewise Threat Intelligence

CVE-2026-9007: HCL Notes reflected cross-site scripting

CVE-2026-9007 · Severity: info · CVSS 5.5 · Published 2026-07-15

Vendors: HCL Software.

Executive brief

HCL Notes, a widely used enterprise collaboration and email client, is vulnerable to a security flaw that could allow an attacker to run malicious scripts in a user's browser or client session. By tricking a user into clicking a specially crafted link, an attacker could potentially steal login session information or perform actions on behalf of the user. This risk primarily impacts the confidentiality and integrity of user data within the application.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in HCL Notes due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is exploitable via the network vector and requires administrative or user interaction, typically involving a victim clicking a malicious link. Successful exploitation allows an attacker to execute arbitrary JavaScript within the security context of the victim's session. The issue specifically affects HCL Notes Release 12.0.2FP5HF8 running on specific Linux kernel versions. While a CVSS 4.0 score of 5.5 has been assigned by the CNA, specific patch availability details were not provided in the advisory.

Affected products

  • HCL Software Notes Release 12.0.2FP5HF8 on Linux 4.18.0-553.52.1.El8_10.X64_64#1

Timeline

  • 2026-07-15: advisory: NVD published the CVE record based on TCS-CERT data.
  • 2026-07-15: disclosed

References