Search/CVE-2025-52642
CVE — Low

CVE-2025-52642

HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure details which could potentially aid in further targeted attacks or information disclosure.

CVSS v3.1
3.3 LOW
EPSS
0.11%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
CVSS v3.1 Detail
Attack VectorLOCAL
Attack ComplexityHIGH
Privileges RequiredLOW
User InteractionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
IntegrityLOW
AvailabilityNONE
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Connections
2 relationships
Timeline
disclosure → media coverage
Mar 16, 2026
Disclosure — published as a CVE record. · last revised by NVD Apr 27, 2026