Description
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.
Published: 2026-06-26
Score: 6.7 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability causes HCL Traveler for Microsoft Outlook libraries to be flagged as malicious or unrecognized software. This misclassification can lead to Outlook disabling or refusing to load the Traveler add‑in, effectively denying users the ability to access email, calendar, or other productivity features. The flaw stems from an inappropriate restriction of functionality, as catalogued by CWE-1104. No direct data‑compromise, code‑execution, or persistence is described, but the loss of functionality constitutes a significant impact on availability for affected users.

Affected Systems

Products affected are HCLSoftware Traveler for Microsoft Outlook. No specific version details were supplied, so the entire product line is considered at risk.

Risk and Exploitability

The CVSS score of 6.7 indicates a moderate risk. The EPSS score is not reported, and the vulnerability is not listed in CISA KEV, suggesting there is no known active exploitation. The likely attack vector is a local or remote user triggering the Outlook application to load the Traveler libraries, which will then be blocked by the operating system or antivirus. Without an exploit, the primary risk is denial of service to legitimate users rather than direct compromise. The vulnerability will only affect systems that have the Traveler add‑in installed and rely on it for Outlook integration.

Generated by OpenCVE AI on June 26, 2026 at 22:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest update or patch for HCL Traveler for Microsoft Outlook released after the advisory at https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131417
  • If a patch is unavailable, temporarily disable the Traveler add‑in in Outlook or configure the operating system’s security settings to whitelist the Traveler libraries
  • Monitor for future advisories or updates from HCLSoftware and apply them promptly when released

Generated by OpenCVE AI on June 26, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 26 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1104 CWE-347

Fri, 26 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Description The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.
Title HCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerability
Weaknesses CWE-1104
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-06-26T23:23:17.558Z

Reserved: 2024-01-18T07:30:10.661Z

Link: CVE-2024-23581

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-26T22:30:04Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature