CVE-2026-9007

  • Cybersecurity
  • Cybersecurity services
  • Belgium
  • Type Cyber Threat Research

Author: Julien BLOMMAERT
Published: 03/08/2026

Abstract Advisory Information

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (XSS). Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of another user.

This issue affects HCL Notes: Release 12.0.2FP5HF8 on Linux 4.18.0-553.52.1.El8_10.X64_64#1.

Author: Julien BLOMMAERT

 

Version affected

Name: HCL Notes

Versions: Release 12.0.2FP5HF8 on Linux 4.18.0-553.52.1.el8_10.x64_64#1

 

Common Vulnerability Scoring System

5.5

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H

 

Patch

No patch available

 

References

  • https://www.cve.org/CVERecord?id=CVE-2026-9007

Vulnerability Disclosure Timeline

  • 22/01/2025: Vulnerability discovery
  • 31/01/2025: Vulnerability Reported to TCS-CERT
  • 04/02/2025: Vulnerability Reported to HCL Software via mail (psirt@hcl-software.com)
  • 11/02/2025: Update asked to HCL (psirt@hcl-software.com)
  • 18/02/2025: Vulnerability Reported to HCL Software via mail (hcl_pnp_support@hcl.com)
  • 25/02/2025: Update asked to HCL 04/03/2025: Vulnerability Report to HCL Psirt (psirt@hcl.com)
  • 06/06/2025: Reported to Thales PSIRT 25/08/2025: Follow the MITRE dispute procedure and sent informations to PSIRT Thales
  • 13/01/2026: MITRE come back to TCS-CERT regarding dispute procedure
  • 15/01/2026: Give permission to MITRE to share vulnerability informations with HCL
  • 16/01/2026: PSIRT@hcl-software.com contacted THA-CERT
  • 16/01/2026: TCS-CERT initiated contact with HCL (PSIRT@hcl-software.com), TCS-CERT asked for a secure communication channel
  • 16/01/2026: HCL wants confirmation that TCS-CERT work behalf a client
  • 21/01/2026: HCL wants TCS-CERT to submit the vulnerability from their customer platform
  • 26/01/2026: Mail sent to HCL to tell that TCS-CERT is unable to use this platform
  • 28/01/2026: HCL refuse to use PGP communication to receive vulnerability
  • 29/01/2026: Reported this case to MITRE
  • 19/05/2026: Thales PSIRT confirmed MITRE agree about vulnerability disclosure
  • 03/08/2026: Expected Vulnerability disclosure