Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L).
Published: 2026-08-18
Score: 3.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the installation and configuration component of Oracle Hyperion Infrastructure Technology and can be exploited by an attacker who has system‑level access on the host where the software runs. Successful exploitation permits an attacker to insert, update, or delete data stored in the application and to cause a partial denial of service. The impact is limited to integrity and availability of the affected data and is presented in the CVSS vector as low confidentiality impact, low integrity impact and low availability impact.

Affected Systems

Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. The vulnerability is only known to affect this specific release of the product from Oracle.

Risk and Exploitability

The CVSS 3.1 base score of 3.4 reflects the low severity of the flaw. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Exploitation requires a local user with high privileges on the host, so the likely attack vector is local access by an account that the application runs under. Because the vulnerability is not remote, the risk depends on the privileges of the local accounts used to run Hyperion and on the security posture of the host system.

Generated by OpenCVE AI on August 19, 2026 at 11:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s official security website for a patch that addresses the flaw and apply it as soon as possible.
  • If a patch is not yet available, upgrade to a later, non‑vulnerable version of Oracle Hyperion Infrastructure Technology if the upgrade path is supported by your environment.
  • Restrict the privileges of the account under which Oracle Hyperion is installed and executed, ensuring it has only the minimum rights required for normal operation.
  • Configure logging and monitoring to detect unauthorized data modification or service interruption in the Hyperion database and alert the security team.

Generated by OpenCVE AI on August 19, 2026 at 11:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title High‑Privilege Local Vulnerability Allowing Unauthorized Data Modification and Partial Denial of Service in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284
CWE-732

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:15.358Z

Reserved: 2026-07-14T14:54:48.742Z

Link: CVE-2026-62569

cve-icon Vulnrichment

Updated: 2026-08-19T12:12:18.535Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:08.677

Modified: 2026-08-24T16:13:03.787

Link: CVE-2026-62569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T11:30:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-732

    Incorrect Permission Assignment for Critical Resource