Executive brief
HCL AION, a platform used for business process automation and AI-driven operations, lacks sufficient protections against repeated login attempts. This flaw allows an attacker on the same local network to perform brute-force attacks against user accounts. If successful, this could lead to unauthorized access to the system, potentially compromising sensitive business data or disrupting operations.
Technical details
HCL AION is vulnerable to improper restriction of excessive authentication attempts (CWE-307). The application fails to implement rate limiting or account lockout mechanisms on its authentication interfaces. An attacker located on the adjacent network can perform automated brute-force or dictionary attacks to guess user credentials. Successful exploitation could result in unauthorized access or account compromise. The vulnerability is addressed in the HCL security bulletin KB0130636.
Affected products
- HCL AION
Timeline
- 2026-05-14: disclosed
- 2026-05-14: advisory