Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology. An attacker who can log onto the host with a low‑privileged account can exploit the vulnerability to read all data that the application makes available, resulting in a high confidentiality impact. Because the flaw changes the affected scope, other products that rely on the same infrastructure may also be exposed. The weakness is a lack of proper authorization checks that allow unauthorized read access to confidential information.

Affected Systems

Oracle Hyperion Infrastructure Technology version 11.2.25.0.000, as distributed by Oracle Corporation, is affected. Systems running this version on a host where local low‑privileged users can log on or execute code are vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 6.5 indicates moderate severity, with high confidentiality impact but limited attacker privileges. The EPSS score of less than 1% suggests that the probability of exploitation is currently low, and the issue is not listed in the CISA KEV catalog. Nonetheless, environments that allow low‑privileged local access remain at risk because the vulnerability is easily exploitable once such an account exists. The likely attack vector is local: a low‑privileged account that can execute code on the host bypasses application‑level checks and exposes all accessible data.

Generated by OpenCVE AI on August 21, 2026 at 11:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security update page for patches applicable to version 11.2.25.0.000
  • Restrict local user permissions to the minimum required, preventing execution of arbitrary binaries or commands
  • Configure and monitor audit logs for unexpected read operations or command executions by low‑privileged accounts

Generated by OpenCVE AI on August 21, 2026 at 11:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Exposure via Local Low‑Privilege Access in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-200
CWE-284

Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Access Leading to Unauthorized Data Exposure in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-250
CWE-284

Wed, 19 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Access Leading to Unauthorized Data Exposure in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-250
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T18:03:32.433Z

Reserved: 2026-07-14T14:54:48.742Z

Link: CVE-2026-62572

cve-icon Vulnrichment

Updated: 2026-08-25T17:56:30.495Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:09.070

Modified: 2026-08-27T17:18:55.113

Link: CVE-2026-62572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:00:11Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control