Vulnerability in HCL Traveler Affecting Apple Mail Profile Configuration
CVE-2026-56547

3.5LOW

Key Information:

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-56547?

The vulnerability relates to the Apple profile created for synchronizing Mail, Calendar, and Contacts through HCL Traveler. During the profile generation, the Logon Name and Mail Address are embedded within the profile. Once set, these values cannot be altered, potentially exposing the system if the inputs are not validated against the Domino directory of the authenticated user. Although the attacker is limited to targeting their own device, the lack of validation during profile creation could lead to unintended security risks.

Affected Version(s)

Traveler <14.5.1.1

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.