Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.3 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).
Published: 2026-08-18
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Common Security component of Oracle Hyperion Infrastructure Technology that can be exploited by an adversary who gains high privileged access over the network. Successful exploitation may allow the attacker to update, insert, or delete data that is normally protected, and can also cause a partial denial of service. The weakness is reflected in a CVSS score of 3.3, indicating that the threat primarily affects data integrity and availability but not confidentiality.

Affected Systems

Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000, is the only version documented as affected.

Risk and Exploitability

The CVSS base score of 3.3 highlights that the exploit is not trivial but poses a legitimate risk to data integrity and system availability. The EPSS score is unavailable, and the vulnerability has not been listed in CISA's KEV catalog. The publicly available description indicates that the attack vector requires network access via HTTP, and the attacker must already possess high privileges. While the vulnerability is considered difficult to exploit, the potential impact warrants proactive mitigation.

Generated by OpenCVE AI on August 19, 2026 at 11:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's latest patch for Oracle Hyperion Infrastructure Technology to remove the vulnerability
  • Restrict network access to the Hyperion service using firewall rules or IP whitelisting to limit HTTP exposure
  • Monitor audit logs for unauthorized data modification or partial denial of service events

Generated by OpenCVE AI on August 19, 2026 at 11:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title High Privilege Access via HTTP Exploitation in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.3 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:15.695Z

Reserved: 2026-07-14T14:54:48.739Z

Link: CVE-2026-62526

cve-icon Vulnrichment

Updated: 2026-08-19T12:12:29.482Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:05.410

Modified: 2026-08-24T16:12:54.170

Link: CVE-2026-62526

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T11:30:04Z

Weaknesses