Indirect Prompt Injection Vulnerability in HCL AION Software
CVE-2026-21832

4.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-21832?

HCL AION is affected by an indirect prompt injection vulnerability that may allow attackers to inject HTML markup into the rendered output. This injected content can be displayed to end users, potentially leading to unexpected behavior or security issues. Attackers could exploit this vulnerability under certain conditions, making it critical for organizations using HCL AION to ensure they have appropriate security measures in place.

Affected Version(s)

AION v2.5.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.