Description
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions.
Published: 2026-08-13
Score: 5.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL AION exposes certain endpoints without sufficient anti‑automation controls, allowing automated or scripted requests to bypass normal rate limiting or challenge mechanisms. This can lead to unintended behavior, operational disruption, or other security impacts if the server processes excessive or malicious traffic.

Affected Systems

The affected product is HCL Software AION; no specific version information was supplied. Users should verify whether their deployment matches the vulnerability scope described in the vendor reference and consult the support article for update details.

Risk and Exploitability

The CVSS score of 5.6 indicates moderate severity, and the lack of an EPSS score leaves the exact exploitation likelihood uncertain. Since the issue involves unauthenticated automated traffic, an attacker can remotely abuse exposed endpoints by sending prolonged or bulk requests, potentially causing unintended behavior or degradation of service. The vulnerability is not listed in CISA KEV, but because the attack can be performed over the network it remains a significant concern for environments with exposed AION instances.

Generated by OpenCVE AI on August 13, 2026 at 15:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review and apply the latest security patch or update for HCL AION as provided in the vendor support article.
  • Implement rate limiting, CAPTCHAs, or token‑based validation on the affected endpoints to deter automated requests.
  • Monitor network traffic for abnormal request patterns, set alerts for spikes, and consider temporarily blocking suspicious activity while a patch is applied.

Generated by OpenCVE AI on August 13, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions.
Title HCL AION is affected by multiple security vulnerabilities.
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-13T15:52:35.543Z

Reserved: 2025-10-10T09:04:16.878Z

Link: CVE-2025-62314

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T14:16:48.047

Modified: 2026-08-13T14:16:48.047

Link: CVE-2025-62314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T15:30:04Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts