CVE-2026-21833: HCL AION is susceptible to a Missing "Content-Security-Policy" header Vulnerability (CVE-2026-21833)
Published Oct 1, 2026
·Updated
HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks such as Cross-Site Scripting (XSS) by restricting the sources from which scripts, styles, and other resources can be loaded. The absence of this header may reduce the effectiveness of browser-based security controls, potentially resulting in unintended behavior or negative security impacts under certain conditions.
Affected Software
1 affected component
HCL AION
Event History
Oct 1, 2026
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to attempt exploitation?
The CVSS vector indicates network access is sufficient, with no privileges or user interaction required. Exploitation is rated high complexity.
2
What is the indicated security impact?
The CVSS assessment indicates low confidentiality impact and no integrity or availability impact. Scope is unchanged.