CVE-2026-9007
Author: Julien BLOMMAERT
Published: 03/08/2026
Abstract Advisory Information
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (XSS). Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of another user.
This issue affects HCL Notes: Release 12.0.2FP5HF8 on Linux 4.18.0-553.52.1.El8_10.X64_64#1.
Author: Julien BLOMMAERT
Version affected
Name: HCL Notes
Versions: Release 12.0.2FP5HF8 on Linux 4.18.0-553.52.1.el8_10.x64_64#1
Common Vulnerability Scoring System
5.5
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Patch
No patch available
References
- https://www.cve.org/CVERecord?id=CVE-2026-9007
Vulnerability Disclosure Timeline
- 22/01/2025: Vulnerability discovery
- 31/01/2025: Vulnerability Reported to TCS-CERT
- 04/02/2025: Vulnerability Reported to HCL Software via mail (psirt@hcl-software.com)
- 11/02/2025: Update asked to HCL (psirt@hcl-software.com)
- 18/02/2025: Vulnerability Reported to HCL Software via mail (hcl_pnp_support@hcl.com)
- 25/02/2025: Update asked to HCL 04/03/2025: Vulnerability Report to HCL Psirt (psirt@hcl.com)
- 06/06/2025: Reported to Thales PSIRT 25/08/2025: Follow the MITRE dispute procedure and sent informations to PSIRT Thales
- 13/01/2026: MITRE come back to TCS-CERT regarding dispute procedure
- 15/01/2026: Give permission to MITRE to share vulnerability informations with HCL
- 16/01/2026: PSIRT@hcl-software.com contacted THA-CERT
- 16/01/2026: TCS-CERT initiated contact with HCL (PSIRT@hcl-software.com), TCS-CERT asked for a secure communication channel
- 16/01/2026: HCL wants confirmation that TCS-CERT work behalf a client
- 21/01/2026: HCL wants TCS-CERT to submit the vulnerability from their customer platform
- 26/01/2026: Mail sent to HCL to tell that TCS-CERT is unable to use this platform
- 28/01/2026: HCL refuse to use PGP communication to receive vulnerability
- 29/01/2026: Reported this case to MITRE
- 19/05/2026: Thales PSIRT confirmed MITRE agree about vulnerability disclosure
- 03/08/2026: Expected Vulnerability disclosure