CVE-2025-52660: Hcltech Aion
Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
Affected products
- Hcltech Aion: version 2.0.0 only
Published 2026-01-19. Last modified 2026-06-17.