Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A difficult‑to‑exploit flaw in the Common Events component of Oracle Hyperion Infrastructure Technology allows an attacker who is unauthenticated and has network access via HTTP to compromise the system, potentially enabling full takeover. This vulnerability arises from improper access control (CWE-284). The flaw is rated with a CVSS 3.1 base score of 8.1 and carries significant confidentiality, integrity, and availability impact. The description indicates that the vulnerability does not require any privileged user credentials and can be triggered from the outside world.

Affected Systems

Oracle Corporation’s Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000, is the only version identified as affected by this vulnerability. No other versions or products are listed in the available CNA data.

Risk and Exploitability

The CVSS score of 8.1 signals a high severity scenario, and the EPSS score of 0.00376 indicates a very low probability of exploitation. The vulnerability is not referenced in the CISA KEV catalog, indicating no confirmed commercial exploitation as of the last update. Attackers would need to send crafted HTTP requests to the compromised instance; no local privileges or additional software are required. Given the ease of remote access over public networks, the risk to exposed installations is considerable until a patch or mitigation is applied.

Generated by OpenCVE AI on August 27, 2026 at 01:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or update Oracle Hyperion Infrastructure Technology to a version that no longer includes version 11.2.25.0.000.
  • Configure firewall or network ACLs to limit HTTP access to the Hyperion service to trusted hosts or internal networks only.
  • Enable monitoring and alerting for anomalous HTTP traffic patterns targeting the Hyperion Infrastructure endpoints to detect potential exploitation attempts.

Generated by OpenCVE AI on August 27, 2026 at 01:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Hyperion Infrastructure Common Events

Thu, 27 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Remote code execution vulnerability in Oracle Hyperion Infrastructure Technology Common Events component
Weaknesses CWE-200
CWE-78

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Remote code execution vulnerability in Oracle Hyperion Infrastructure Technology Common Events component
Weaknesses CWE-200
CWE-78

Fri, 21 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploit in Oracle Hyperion Infrastructure
Weaknesses CWE-287

Wed, 19 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploit in Oracle Hyperion Infrastructure
Weaknesses CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T17:34:47.340Z

Reserved: 2026-07-14T14:54:48.737Z

Link: CVE-2026-62501

cve-icon Vulnrichment

Updated: 2026-08-26T17:31:04.745Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:04.227

Modified: 2026-08-27T17:22:16.063

Link: CVE-2026-62501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T02:00:14Z

Weaknesses