CVE-2026-21833
Received Received - Intake

Missing Content-Security-Policy Header in HCL AION

Vulnerability report for CVE-2026-21833, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: HCL Software

Description

HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks such as Cross-Site Scripting (XSS) by restricting the sources from which scripts, styles, and other resources can be loaded. The absence of this header may reduce the effectiveness of browser-based security controls, potentially resulting in unintended behavior or negative security impacts under certain conditions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcl aion *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1032

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HCL AION lacks a Content-Security-Policy (CSP) HTTP response header. CSP restricts sources for scripts and resources to prevent attacks like Cross-Site Scripting (XSS). Without it, browser-based security controls are weakened, increasing risk of unintended behavior or security impacts.

Detection Guidance

To detect the missing Content-Security-Policy header, use tools like curl or browser developer tools. For example, run: curl -I http://your-server-address. This will show HTTP response headers. Check if 'Content-Security-Policy' is present. Alternatively, use browser dev tools (Network tab) to inspect headers for the response.

Impact Analysis

The absence of CSP may allow XSS attacks, enabling attackers to execute malicious scripts in your browser. This could lead to data theft, session hijacking, or unauthorized actions on affected systems.

Compliance Impact

The vulnerability does not directly affect compliance with GDPR or HIPAA. However, the absence of a Content-Security-Policy header may reduce browser-based security controls, potentially increasing risks like Cross-Site Scripting (XSS), which could indirectly impact compliance by weakening data protection measures.

Mitigation Strategies

Implement a Content-Security-Policy header on your HCL AION server. Configure it to restrict sources for scripts, styles, and other resources. Refer to HCL's security bulletin for specific policy recommendations and ensure proper testing before deployment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21833. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart