Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech aion |
|
| Vendors & Products |
Hcltech
Hcltech aion |
Thu, 01 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks such as Cross-Site Scripting (XSS) by restricting the sources from which scripts, styles, and other resources can be loaded. The absence of this header may reduce the effectiveness of browser-based security controls, potentially resulting in unintended behavior or negative security impacts under certain conditions. | |
| Title | HCL AION is susceptible to a Missing "Content-Security-Policy" header Vulnerability (CVE-2026-21833) | |
| Weaknesses | CWE-1032 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-10-01T18:03:33.734Z
Reserved: 2026-01-05T16:08:25.000Z
Link: CVE-2026-21833
Updated: 2026-10-01T18:03:26.427Z
Status : Received
Published: 2026-10-01T17:17:23.380
Modified: 2026-10-01T19:17:20.117
Link: CVE-2026-21833
No data.
OpenCVE Enrichment
Updated: 2026-10-01T19:33:33Z
