Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the installation and configuration component of Oracle Hyperion Infrastructure Technology 11.2.25.0.000 and allows an unauthenticated attacker with network access over HTTP to gain unauthorized access to all data exposed by the product. While the description indicates that the attacker could potentially gain full control, this is inferred rather than directly stated, and the risk is that the attacker could achieve complete compromise of the Hyperion environment. This weakness corresponds to an access control vulnerability.

Affected Systems

Affected vendors include Oracle Corporation. The vulnerable product is Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. No other versions are explicitly listed as affected in this advisory.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 underscores a high severity threat with a network-access (AV:N) vector and low attack complexity (AC:L). The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely abused. Nevertheless, because no authentication is required and an HTTP interface is exposed, it is inferred that an internal or external attacker with network connectivity could potentially exploit this flaw.

Generated by OpenCVE AI on August 26, 2026 at 23:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch for Oracle Hyperion Infrastructure Technology 11.2.25.0.000 when released.
  • Restrict HTTP access to the Hyperion server to trusted internal networks only.
  • Disable or limit the installation and configuration interface if not needed.

Generated by OpenCVE AI on August 26, 2026 at 23:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Access in Oracle Hyperion Infrastructure Technology

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 26 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Access in Oracle Hyperion Infrastructure Technology

Wed, 26 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Access in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Access in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:26:12.586Z

Reserved: 2026-07-14T14:54:48.740Z

Link: CVE-2026-62550

cve-icon Vulnrichment

Updated: 2026-08-26T13:52:36.454Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:07.300

Modified: 2026-08-26T16:16:33.163

Link: CVE-2026-62550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T23:00:14Z

Weaknesses