Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A difficult‑to‑exploit flaw in the Common Events component of Oracle Hyperion Infrastructure Technology allows an attacker who is unauthenticated and has network access via HTTP to compromise the system, potentially enabling full takeover. The flaw is rated with a CVSS 3.1 base score of 8.1 and carries significant confidentiality, integrity, and availability impact. The description indicates that the vulnerability does not require any privileged user credentials and can be triggered from the outside world.

Affected Systems

Oracle Corporation’s Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000, is the only version identified as affected by this vulnerability. No other versions or products are listed in the available CNA data.

Risk and Exploitability

The CVSS score of 8.1 signals a high severity scenario, and although an EPSS score is not provided, the lack of availability suggests that exploitation is feasible under the right network conditions. The vulnerability is not referenced in the CISA KEV catalog, indicating no confirmed commercial exploitation as of the last update. Attackers would need to send crafted HTTP requests to the compromised instance; no local privileges or additional software are required. Given the ease of remote access over public networks, the risk to exposed installations is considerable until a patch or mitigation is applied.

Generated by OpenCVE AI on August 19, 2026 at 00:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or update Oracle Hyperion Infrastructure Technology to a version that no longer includes version 11.2.25.0.000.
  • Configure firewall or network ACLs to limit HTTP access to the Hyperion service to trusted hosts or internal networks only.
  • Enable monitoring and alerting for anomalous HTTP traffic patterns targeting the Hyperion Infrastructure endpoints to detect potential exploitation attempts.

Generated by OpenCVE AI on August 19, 2026 at 00:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploit in Oracle Hyperion Infrastructure
Weaknesses CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:00:19.812Z

Reserved: 2026-07-14T14:54:48.737Z

Link: CVE-2026-62501

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:04.227

Modified: 2026-08-18T21:17:04.227

Link: CVE-2026-62501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:30:04Z

Weaknesses