Description
HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks such as Cross-Site Scripting (XSS) by restricting the sources from which scripts, styles, and other resources can be loaded. The absence of this header may reduce the effectiveness of browser-based security controls, potentially resulting in unintended behavior or negative security impacts under certain conditions.
Published: 2026-10-01
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: Browser security downgrade
Action: Apply patch
AI Analysis

Impact

HCL AION exposes a missing Content-Security-Policy HTTP response header, a control that normally limits the origins from which scripts, styles, and other resources can be loaded. Without this header, the web application no longer actively blocks potentially unsafe content, which can reduce the effectiveness of browser defenses against cross‑site scripting and related injection attacks. The vulnerability could therefore allow attackers to leverage vulnerable browsers to inject or execute arbitrary scripts in the context of the application, resulting in confidentiality or integrity compromises under certain conditions.

Affected Systems

The affected product is HCL Software AION. No specific version ranges are listed, so all installations of AION may be impacted until a patch or configuration fix is applied.

Risk and Exploitability

The CVSS score of 3.7 indicates a low overall severity. The EPSS score is not available and the weakness is not listed in the CISA KEV catalog. Likely attack vector is through a victim’s browser; an attacker would need to deliver malicious content to a browser that accesses the affected application. Because the vulnerability only removes a mitigative header, exploitation requires a separate XSS vector, and the risk is considered low but not negligible.

Generated by OpenCVE AI on October 1, 2026 at 19:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest HCL AION security update that includes the missing Content‑Security‑Policy header.
  • If a patch is unavailable, configure the application or web server to add a Content‑Security‑Policy header that restricts script sources to trusted origins.
  • Enable additional browser‑side protections, such as the XSS Auditor or script‑content restrictions, to reduce the impact until a proper header is deployed.

Generated by OpenCVE AI on October 1, 2026 at 19:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks such as Cross-Site Scripting (XSS) by restricting the sources from which scripts, styles, and other resources can be loaded. The absence of this header may reduce the effectiveness of browser-based security controls, potentially resulting in unintended behavior or negative security impacts under certain conditions.
Title HCL AION is susceptible to a Missing "Content-Security-Policy" header Vulnerability (CVE-2026-21833)
Weaknesses CWE-1032
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-10-01T18:03:33.734Z

Reserved: 2026-01-05T16:08:25.000Z

Link: CVE-2026-21833

cve-icon Vulnrichment

Updated: 2026-10-01T18:03:26.427Z

cve-icon NVD

Status : Received

Published: 2026-10-01T17:17:23.380

Modified: 2026-10-01T19:17:20.117

Link: CVE-2026-21833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:15:12Z

Weaknesses