Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology allows a low-privileged user who has logged onto the host to read data that it otherwise would not be able to access. The vulnerability is rooted in improper access control and insufficient permission checks, permitting disclosure of sensitive information while leaving integrity and availability untouched.

Affected Systems

The product affected is Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. Users with local logon rights but not full administrative privileges can exploit the flaw during the installation and configuration phase, potentially accessing all data exposed by the product.

Risk and Exploitability

The CVSS v3.1 base score of 5.5, generated from a vector of AV:L/AC:L/PR:L/UI:N/S:U/C:H, indicates moderate severity limited to confidentiality. The EPSS score of < 1% shows a very low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. Because the attack requires local access with low privileges and no user interaction, any non-administrator who logs onto the machine could potentially activate the disclosure path, making the risk relatively high in environments where local logons are granted broadly.

Generated by OpenCVE AI on August 26, 2026 at 05:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Limit local logon privileges to trusted administrators only, preventing ordinary users from accessing the installation and configuration process.
  • Enforce strict role-based access controls and audit configuration changes to detect and respond to unauthorized attempts.
  • Stay informed of Oracle security announcements and apply any future patches or update releases when they become available.

Generated by OpenCVE AI on August 26, 2026 at 05:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Access Reads Confidential Data in Oracle Hyperion Infrastructure

Wed, 26 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Local Privileged User Information Disclosure in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-200
CWE-276

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Title Local Privileged User Information Disclosure in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-200
CWE-276

Fri, 21 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local Privileged Access Allows Confidential Data Exposure in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284

Wed, 19 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Local Privileged Access Allows Confidential Data Exposure in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T18:03:33.275Z

Reserved: 2026-07-14T14:54:48.741Z

Link: CVE-2026-62553

cve-icon Vulnrichment

Updated: 2026-08-25T17:56:40.687Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:07.727

Modified: 2026-08-25T18:17:57.520

Link: CVE-2026-62553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T06:00:12Z

Weaknesses