Executive brief
HCL AION is an enterprise software platform that is currently affected by a security weakness in how it handles user logins. The system uses a basic authentication method that can allow an attacker on the same local network to intercept and steal user credentials. If exploited, this could lead to unauthorized access to the platform and the sensitive business data it manages.
Technical details
HCL AION utilizes an insecure authentication mechanism (CWE-522) by relying on basic authorization tokens. This implementation is susceptible to credential interception, particularly if the communication channel is not sufficiently encrypted or if an attacker is positioned on the adjacent network. According to the CVSS vector, the attack requires low privileges and user interaction from a target on the same local network. An attacker successfully exploiting this flaw could gain access to user credentials, leading to a loss of confidentiality. Users are advised to refer to HCL's official security bulletin for remediation steps.
Affected products
- HCL AION
Timeline
- 2026-05-14: disclosed: Initial disclosure by HCL Software
- 2026-05-14: advisory: NVD publication date