Content Security Policy Misconfiguration in HCL AION
CVE-2026-21833

3.7LOW

Key Information:

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-21833?

HCL AION suffers from a critical misconfiguration where the Content-Security-Policy (CSP) HTTP response header is absent. This header is crucial for safeguarding web applications against various attacks, including Cross-Site Scripting (XSS). Without a properly configured CSP, malicious actors may exploit this vulnerability to manipulate content or execute unauthorized scripts, thus undermining the application's security posture and potentially leading to data breaches. It is essential for users of HCL AION to address this issue to reinforce their web security measures.

Affected Version(s)

AION Version 2.5.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.