Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-08-18
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from a flaw in the Common Security component of Oracle Hyperion Infrastructure Technology. It permits an unauthenticated attacker who can reach the application over HTTP to perform unauthorized updates, inserts, or deletions of data, as well as read restricted data. The flaw is a direct result of improper access control that allows input from non‑authenticated users to influence privileged operations, leading to confidentiality and integrity violations.

Affected Systems

The affected product is Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. Only this version is explicitly listed as vulnerable, and no other versions or components are noted as impacted.

Risk and Exploitability

The CVSS 3.1 score of 6.1 indicates moderate severity, with the vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L. Exploitation requires a human click or interaction, but once triggered it can modify data across the scope. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog, meaning there is limited evidence of widespread exploitation. However, because it allows an unauthenticated user to access the system over the network and modifies data, organizations should treat it as potentially high risk if the product is exposed to external networks.

Generated by OpenCVE AI on August 19, 2026 at 00:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security notice and apply any released patch for Hyperion Infrastructure Technology 11.2.25.0.000.
  • Limit HTTP access to the Hyperion web interface by restricting it to trusted IP ranges or VPN only.
  • Enable and review audit logs for unauthorized data modification or read attempts, and enforce strict role‑based access controls within the application.

Generated by OpenCVE AI on August 19, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title HTTP-Based Unauthorized Data Modification in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:00:19.092Z

Reserved: 2026-07-14T14:54:48.737Z

Link: CVE-2026-62499

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:03.990

Modified: 2026-08-18T21:17:03.990

Link: CVE-2026-62499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:30:04Z

Weaknesses