Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).
Published: 2026-08-18
Score: 3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Hyperion Infrastructure Technology installation and configuration component contains a missing access control flaw that allows a user who has already logged on with high privileges to modify, delete, or insert data. An attacker can also trigger a partial denial of service against the application. The vulnerability does not enable privilege escalation; it simply extends the capabilities of an existing high‑privileged account, leading to data tampering and limited availability disruption.

Affected Systems

Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000, is affected. The product is provided by Oracle Corporation and is the only product impacted by this advisory.

Risk and Exploitability

The CVSS 3.1 base score of 3.0 indicates a low overall severity, but it highlights integrity and availability impacts. The EPSS score is less than 1%, suggesting a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires local access (AV:L) and a high‑privilege account (PR:H), exploitation is limited to users who already have elevated permissions on the system, reducing the overall threat exposure but still posing a risk to the data integrity of the installed system.

Generated by OpenCVE AI on August 21, 2026 at 11:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a fixed version of Hyperion Infrastructure Technology as released by Oracle.
  • If an upgrade cannot be performed immediately, restrict high‑privilege user accounts to the minimum necessary permissions for Hyperion operation and enforce least‑privilege access controls.
  • Verify that the infrastructure is configured to prevent unintended partial denial of service triggers, such as logging and monitoring of anomalous requests, and apply any recommended configuration hardening from Oracle.

Generated by OpenCVE AI on August 21, 2026 at 11:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Infrastructure Vulnerability Enables High‑Privilege Data Modification and Partial Service Interruption

Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title High Privileged Local Access Control Vulnerability in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-285

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title High Privileged Local Access Control Vulnerability in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:15.184Z

Reserved: 2026-07-14T14:54:48.742Z

Link: CVE-2026-62570

cve-icon Vulnrichment

Updated: 2026-08-19T12:12:14.568Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:08.837

Modified: 2026-08-24T16:13:09.967

Link: CVE-2026-62570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T11:45:04Z

Weaknesses