Description
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions.
Published: 2026-08-13
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL AION exposes certain endpoints without sufficient anti‑automation controls, allowing automated or scripted requests to bypass normal rate limiting or challenge mechanisms. This can lead to unintended behavior, operational disruption, or other security impacts if the server processes excessive or malicious traffic.

Affected Systems

The affected product is HCL Software AION; no specific version information was supplied. Users should verify whether their deployment matches the vulnerability scope described in the vendor reference and consult the support article for update details.

Risk and Exploitability

The CVSS score of 5.6 indicates moderate severity, and the lack of an EPSS score leaves the exact exploitation likelihood uncertain. Since the issue involves unauthenticated automated traffic, an attacker can remotely abuse exposed endpoints by sending prolonged or bulk requests, potentially causing unintended behavior or degradation of service. The vulnerability is not listed in CISA KEV, but because the attack can be performed over the network it remains a significant concern for environments with exposed AION instances.

Generated by OpenCVE AI on August 13, 2026 at 15:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review and apply the latest security patch or update for HCL AION as provided in the vendor support article.
  • Implement rate limiting, CAPTCHAs, or token‑based validation on the affected endpoints to deter automated requests.
  • Monitor network traffic for abnormal request patterns, set alerts for spikes, and consider temporarily blocking suspicious activity while a patch is applied.

Generated by OpenCVE AI on August 13, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech aion
Vendors & Products Hcltech
Hcltech aion

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions.
Title HCL AION is affected by multiple security vulnerabilities.
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-13T15:52:35.543Z

Reserved: 2025-10-10T09:04:16.878Z

Link: CVE-2025-62314

cve-icon Vulnrichment

Updated: 2026-08-13T15:52:30.632Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T14:16:48.047

Modified: 2026-08-28T16:08:09.497

Link: CVE-2025-62314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T09:32:23Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts