CVE-2026-21833
HCL AION is susceptible to a Missing "Content-Security-Policy" header Vulnerability (CVE-2026-21833)
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks such as Cross-Site Scripting (XSS) by restricting the sources from which scripts, styles, and other resources can be loaded. The absence of this header may reduce the effectiveness of browser-based security controls, potentially resulting in unintended behavior or negative security impacts under certain conditions.
| CWE | CWE-1032 |
| Vendor | hcl software |
| Product | aion |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for hcl software aion
Be the first to know when new low vulnerabilities affecting hcl software aion are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
HCL Software / AION
Version 2.5.0