CVE-2025-52633CWE-539
HCL AION is susceptible to Missing Content-Security-Policy
Low · published February 3, 2026
What it is
HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent cookies may increase the risk of unauthorized access if the cookies are intercepted or compromised. This issue affects AION: 2.0.
The record
Technical detail
- CVSS v3.1
- 3.1 · LOW
- Vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L
- CVSS v4.0
- Not supplied
- EPSS
- 0.00186 · 8.3th percentile
- Weakness
- CWE-539 · Use of Persistent Cookies Containing Sensitive Information
- Published
- 2026-02-03T18:00Z
EPSS history
Timeline