Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Hyperion Infrastructure Technology contains an installation and configuration flaw that allows an unauthenticated attacker with network access via HTTP to gain unauthorized read access to all data exposed by the product. The vulnerability is exploitable remotely and results in a confidentiality breach, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H. No impact on integrity or availability is described.

Affected Systems

The affected product is Oracle Hyperion Infrastructure Technology version 11.2.25.0.000, distributed by Oracle Corporation.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 indicates high severity, but the EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is listed as not in the CISA KEV catalog. Attackers can exploit it from any device with HTTP connectivity to the affected system, without authentication or user interaction. Given the lack of mitigation from the vendor besides a patch, the risk remains significant until the update is applied.

Generated by OpenCVE AI on August 26, 2026 at 04:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s patch for version 11.2.25.0.000 to address the installation and configuration flaw
  • Restrict HTTP access to the Hyperion server using firewalls or network segmentation until the patch is in place
  • Update network access controls to require VPN or IP whitelisting for Hyperion server use

Generated by OpenCVE AI on August 26, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Allows Remote Unauthorized Data Access in Oracle Hyperion Infrastructure Technology

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Allows Remote Unauthorized Data Access in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T18:03:33.438Z

Reserved: 2026-07-14T14:54:48.741Z

Link: CVE-2026-62552

cve-icon Vulnrichment

Updated: 2026-08-25T17:56:42.735Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:07.600

Modified: 2026-08-25T18:17:57.367

Link: CVE-2026-62552

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T04:30:16Z

Weaknesses