Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Oracle Hyperion Infrastructure Technology product allows an unauthenticated attacker to compromise the system over HTTP, potentially exposing critical data. The flaw resides in the Lifecycle Management component and results in confidentiality violations only, since the CVSS vector indicates no integrity or availability impact. The vulnerability is readily exploitable for unauthorized data access, as the attacker does not need credentials or user interface interaction.

Affected Systems

The affected system is Oracle Corporation's Hyperion Infrastructure Technology, specifically version 11.2.25.0.000. This version of the product is susceptible to the reported flaw.

Risk and Exploitability

With a CVSS score of 7.5, the vulnerability is considered high severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. An attacker with network access can exploit this flaw without authentication, directly over HTTP, to read sensitive data. The risk is elevated for environments that expose the Hyperion service to untrusted networks or lack additional access controls.

Generated by OpenCVE AI on August 18, 2026 at 23:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for Hyperion Infrastructure Technology 11.2.25.0.000 once it becomes available, ensuring the vulnerability is fixed.
  • If a patch is not yet released, restrict HTTP access to the Hyperion service by employing a firewall or reverse proxy that limits traffic to trusted IP ranges.
  • Review and strengthen access control policies for the Hyperion Lifecycle Management component, enforcing proper authentication and authorization to mitigate CWE-284 and CWE-285 weaknesses.

Generated by OpenCVE AI on August 18, 2026 at 23:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access for Data Compromise in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:58:53.962Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60393

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:37.633

Modified: 2026-08-18T21:16:37.633

Link: CVE-2026-60393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:15:04Z

Weaknesses