Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in Oracle Hyperion Infrastructure Technology allows an unauthenticated attacker to compromise the system over HTTP, potentially exposing critical data. The flaw resides in the Lifecycle Management component and results in confidentiality violations only, as illustrated by the CVSS vector indicating no integrity or availability impact. The vulnerability is readily exploitable for unauthorized data access, as the attacker does not need credentials or user interface interaction.

Affected Systems

The affected system is Oracle Corporation's Hyperion Infrastructure Technology, specifically version 11.2.25.0.000. This version of the product is susceptible to the reported flaw.

Risk and Exploitability

With a CVSS score of 7.5, the vulnerability is considered high severity. The EPSS score of < 1% indicates a low but non‑zero probability of exploitation, and the flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. An attacker with network access can exploit this flaw without authentication, directly over HTTP, to read sensitive data. The risk is elevated for environments that expose the Hyperion service to untrusted networks or lack additional access controls.

Generated by OpenCVE AI on August 21, 2026 at 17:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for Hyperion Infrastructure Technology 11.2.25.0.000 once it becomes available, ensuring the vulnerability is fixed.
  • If a patch is not yet released, restrict HTTP access to the Hyperion service by employing a firewall or reverse proxy that limits traffic to trusted IP ranges.
  • Review and strengthen access control policies for the Hyperion Lifecycle Management component, ensuring proper authentication and authorization to protect against information disclosure (CWE-200).

Generated by OpenCVE AI on August 21, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Exposure in Oracle Hyperion Infrastructure Technology 11.2.25

Fri, 21 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access for Data Compromise in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284
CWE-285

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access for Data Compromise in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T14:32:52.197Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60393

cve-icon Vulnrichment

Updated: 2026-08-20T14:32:45.792Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:37.633

Modified: 2026-08-25T16:11:48.177

Link: CVE-2026-60393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T18:00:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor