CVE-2026-56547
Received Received - Intake

Apple Profile Generation Reflected Values in HCL Traveler

Vulnerability report for CVE-2026-56547, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: HCL Software

Description

The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embedded in them.Β  The values cannot be changed later on, so the Apple profile generation page asks for those values and reflects them back in the generated Apple profile.Β  The Apple profile is not usable without additional information and only allows the attacker to attack their own device, but HCL Traveler could at least check that the values submitted and reflected back in the Apple profile are found in the Domino directory entry for the already authenticated user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcl traveler *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Apple profiles generated for Mail, Calendar, and Contacts accounts to sync with HCL Traveler. The profiles embed the Logon Name and Mail Address, which cannot be changed later. The issue is that HCL Traveler does not verify if these values match the authenticated user's directory entry, potentially allowing misuse.

Detection Guidance

This vulnerability involves Apple profile generation for HCL Traveler accounts where Logon Name and Mail Address are embedded without validation. Detection requires checking Apple profile generation pages for improperly reflected user input in HCL Traveler configurations.

Impact Analysis

The vulnerability primarily allows an attacker to attack their own device since the Apple profile is unusable without additional information. It does not directly impact other users or systems, but it could lead to misconfiguration or unintended data exposure if exploited.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it only allows an authenticated user to attack their own device by embedding their Logon Name and Mail Address in an Apple profile. There is no evidence of unauthorized data exposure or impact on regulated data handling.

Mitigation Strategies

Implement server-side validation to ensure submitted Logon Name and Mail Address values match authenticated user entries in the Domino directory. Restrict Apple profile generation to validated fields only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56547. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart