Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the installation and configuration component of Oracle Hyperion Infrastructure Technology, permitting an unauthenticated attacker with network access to gain full control over the system. Successful exploitation can lead to unauthorized access to critical data or complete access to all data stored in the Hyperion platform. The weakness directly impacts confidentiality, with no immediate integrity or availability effects.

Affected Systems

Oracle Corporation’s Hyperion Infrastructure Technology, version 11.2.25.0.000, is the only version explicitly affected. The vulnerability is within the installation and configuration component that is common to all Oracle Hyperion environments deploying this version. No other vendor or product versions are indicated as impacted from the current data. Additionally, the vulnerability’s scope change may affect other products beyond the Hyperion platform.

Risk and Exploitability

The CVSS 3.1 base score of 8.6 indicates high severity, and the vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N) shows that an unauthenticated attacker can remotely exploit the flaw through multiple network protocols. EPSS is < 1%, indicating a very low but non‑zero probability of exploitation; however, the lack of a KEV listing does not diminish the seriousness of the issue. The vulnerability’s scope change may allow attackers to impact additional products beyond Hyperion, and publicly disclosed nature and the common vector suggest potential exposure in enterprise environments. Attackers could exploit this weakness by sending crafted configuration requests from any accessible network segment, bypassing authentication, and assuming system‑wide rights.

Generated by OpenCVE AI on August 26, 2026 at 04:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle‑released security updates for Hyperion Infrastructure Technology as they become available.
  • Restrict network access to the Hyperion installation interface to trusted IP ranges using firewalls or VPNs, enabling only the minimal set of protocols required for operation.
  • Enable comprehensive logging of authentication and configuration changes, and regularly review logs for anomalous activity.

Generated by OpenCVE AI on August 26, 2026 at 04:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Allows Complete Control of Oracle Hyperion Infrastructure Technology

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Allows Complete Control of Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:27:11.603Z

Reserved: 2026-07-14T14:54:48.739Z

Link: CVE-2026-62535

cve-icon Vulnrichment

Updated: 2026-08-26T13:52:34.346Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:06.020

Modified: 2026-08-26T16:16:31.930

Link: CVE-2026-62535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T04:30:16Z

Weaknesses