Executive brief
HCL AION, a platform used for business process automation and AI-driven insights, is affected by a security vulnerability that leaks sensitive backend infrastructure details. This exposure could reveal internal system architecture or configuration settings to unauthorized parties. While not directly granting control over the system, this information provides a roadmap for attackers to plan more sophisticated, targeted attacks against the organization's internal network.
Technical details
HCL AION is vulnerable to an information disclosure flaw (CWE-201) where sensitive backend infrastructure details are inserted into sent data. The vulnerability requires an attacker to have an adjacent network position, low-level privileges, and involves high complexity with a requirement for user interaction. If exploited, the flaw reveals internal system architecture and configuration details. This information leakage can be used to facilitate further reconnaissance or targeted exploitation of the environment. HCL has acknowledged the issue in security bulletin KB0130636.
Affected products
- HCL AION
Timeline
- 2026-05-14: disclosed: Initial disclosure by HCL Software
- 2026-05-14: advisory: NVD publication date