Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Common Events component of Oracle Hyperion Infrastructure Technology that allows an unauthenticated attacker with network access over HTTP to modify, delete, or insert data while also being able to read a portion of the system’s data. The flaw results in a loss of confidentiality and integrity for affected data, with no direct impact on availability reported at this time.

Affected Systems

The affected product is Oracle Hyperion Infrastructure Technology from Oracle Corporation, version 11.2.25.0.000, as identified via the Common Platform Enumeration string for that release.

Risk and Exploitability

The CVSS v3.1 score of 4.8 indicates moderate severity, with medium complexity and no authentication required. Although the EPSS score is not available, the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting it is not actively targeted in the wild yet. An attacker who can reach the application over HTTP could exploit the flaw to gain unauthorized read and write access to sensitive business data simply by sending crafted requests, potentially compromising data integrity and leaking confidential information.

Generated by OpenCVE AI on August 21, 2026 at 10:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Hyperion Infrastructure Technology security patch where instructed by Oracle
  • Restrict network exposure of the Hyperion application by disabling or protecting HTTP access with firewall rules or VPN requirements
  • Enforce strict role‑based access control and audit logging to detect and prevent unauthorized data manipulation

Generated by OpenCVE AI on August 21, 2026 at 10:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via HTTP in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-200
CWE-269
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T17:34:46.073Z

Reserved: 2026-07-14T14:54:48.738Z

Link: CVE-2026-62520

cve-icon Vulnrichment

Updated: 2026-08-26T17:28:25.934Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:05.057

Modified: 2026-08-27T17:20:38.143

Link: CVE-2026-62520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T10:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control