Potential Command Injection Vulnerability in HCL AION
CVE-2025-52626

4.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 February 2026

What is CVE-2025-52626?

A potential command injection vulnerability has been identified in HCL AION 2.0. This vulnerability allows attackers to execute unintended commands on the affected system, which may lead to unauthorized actions and compromise the integrity of system operations. Organizations using HCL AION should promptly assess their exposure and take necessary steps to mitigate the risks associated with this vulnerability.

Affected Version(s)

AION 2.0

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.