HCL AION Audit Log Deficiency (CVE-2025-52644)
CVE-2025-52644 Published on March 16, 2026

HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged.
HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation processes.

NVD

Vulnerability Analysis

CVE-2025-52644 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a high impact on integrity, and a small impact on availability.

Attack Vector:
LOCAL
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
HIGH
Availability Impact:
LOW

Weakness Type

Insufficient Logging

When a security-critical event occurs, the software either does not record the event or omits important details about the event when logging it. When security-critical events are not logged properly, such as a failed login attempt, this can make malicious behavior more difficult to detect and may hinder forensic analysis after an attack succeeds.


Products Associated with CVE-2025-52644

Want to know whenever a new CVE is published for Hcl Aion? stack.watch will email you.

 

Affected Versions

HCL AION Version 2.0 is affected by CVE-2025-52644

Exploit Probability

EPSS
0.05%
Percentile
14.94%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.