CVE-2025-52640 PUBLISHED

HCL AION is affected by multiple security vulnerabilities.

Assigner: HCL
Reserved: 18.06.2025 Published: 13.08.2026 Updated: 13.08.2026

HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended behavior or security impact under certain conditions.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L
CVSS Score: 4.7

Product Status

Vendor HCL Software
Product AION
Versions Default: unaffected
  • Version v2.0 is affected

References

Problem Types

  • CWE- CWE