CVE-2025-62316: Hcl Aion

Low severity, CVSS 2.3. EPSS: 0.1% chance of exploitation in the next 30 days.

HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers may reduce the effectiveness of browser-based security controls and could expose the application to limited security risks under specific conditions.

Affected products

  • Hcl Aion: version 2.1.0 only

Published 2026-05-14. Last modified 2026-10-07.