Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Hyperion Infrastructure Technology is vulnerable to remote code execution flaw that exploits unauthenticated HTTP access in its installation and configuration component. The weakness allows an attacker to take full control of the system, compromising confidentiality, integrity, and availability. The issue was assigned a CVSS v3.1 base score of 9.8, indicating a critical level of risk and the potential for a total system takeover.

Affected Systems

Vulnerability affects Oracle Hyperion Infrastructure Technology version 11.2.25.0.000.

Risk and Exploitability

The flaw is exploitable via an unauthenticated HTTP interface, but the CVE does not explicitly state whether the interface is publicly exposed. Based on the description, it is inferred that the service may be reachable from the internet, making it a likely public HTTP attack vector. The EPSS score of <1% indicates a very low probability of exploitation, yet the CVSS score of 9.8 underscores its high severity. The vulnerability is not listed in the CISA KEV catalog, but its critical nature and direct access vector suggest an adversary could mount an attack quickly and successfully if the system is exposed to the internet.

Generated by OpenCVE AI on August 27, 2026 at 01:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle's support resources for any available fixes and apply them when released
  • Configure network firewalls or ACLs to block public HTTP traffic to the Hyperion service, restricting access to trusted internal networks only
  • Enable authentication mechanisms or restrict administrative interfaces to prevent unauthenticated access

Generated by OpenCVE AI on August 27, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Hyperion Infrastructure Technology

Wed, 26 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unauthenticated HTTP Access in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-287

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 26 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unauthenticated HTTP Access in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-287

Wed, 26 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Hyperion Infrastructure Technology via HTTP
Weaknesses CWE-284

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Hyperion Infrastructure Technology via HTTP
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:26:26.894Z

Reserved: 2026-07-14T14:54:48.740Z

Link: CVE-2026-62544

cve-icon Vulnrichment

Updated: 2026-08-26T13:50:40.208Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:06.947

Modified: 2026-08-26T16:16:32.900

Link: CVE-2026-62544

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T02:00:14Z

Weaknesses