Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Hyperion Infrastructure Technology product contains a defect in its Common Security component that permits an attacker with low privileges to connect over HTTP and create, delete, or alter critical data. The vulnerability enables the attacker to gain full write access to any data accessible through the Hyperion infrastructure, delivering both confidentiality and integrity breaches without impacting availability.

Affected Systems

Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. Users of this release should ensure that their instances are neither exposed to the internet nor accessible to untrusted networks.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates high severity with significant confidentiality and integrity impact. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation yet. However, the vector AV:N/AC:L/PR:L/UI:N indicates that a remote attacker can exploit this with minimal effort and only network access, making the risk substantial for exposed deployments.

Generated by OpenCVE AI on August 19, 2026 at 00:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch addressing CVE-2026-62477 or upgrade to a supported release that eliminates the identified flaw.
  • Restrict HTTP access to the Hyperion application layer to trusted IPs or through a VPN to limit exposure for low‑privileged users.
  • Enforce strict role‑based permissions and audit logs for data modification activities to ensure that only authorized accounts can perform write operations.

Generated by OpenCVE AI on August 19, 2026 at 00:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privilege HTTP Access in Oracle Hyperion
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:00:17.467Z

Reserved: 2026-07-14T14:54:48.734Z

Link: CVE-2026-62477

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:03.410

Modified: 2026-08-18T21:17:03.410

Link: CVE-2026-62477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:30:04Z

Weaknesses