CVE-2025-52661: Medium severity HCL AION vulnerability
Published Jan 19, 2026
·Updated
HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in unauthorized access if the token is compromised.
Affected Software
2 affected components
HCL AION
hcltech Aion=2.0.0
Event History
Jan 19, 2026
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52661?
CVE-2025-52661 is considered a significant vulnerability due to the risk of unauthorized access resulting from prolonged JWT token expiry.
2
How do I fix CVE-2025-52661?
To mitigate CVE-2025-52661, adjust the JWT token expiry settings in HCL AION to a more secure duration.
3
What impact does CVE-2025-52661 have on HCL AION?
CVE-2025-52661 can lead to token misuse, increasing the risk of unauthorized access to systems using HCL AION.
4
Is CVE-2025-52661 remotely exploitable?
Yes, CVE-2025-52661 can potentially be exploited remotely if the JWT token is compromised.
5
What versions of HCL AION are affected by CVE-2025-52661?
CVE-2025-52661 affects HCL AION version 2 and potentially later versions if not patched.