Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows a low‑privileged attacker who can log on to the infrastructure hosting Oracle Hyperion Infrastructure Technology to compromise the application. Successful exploitation leads to unauthorized access to critical data or full access to all Hyperion‑accessible data. The weakness is an improper authorization control in the installation and configuration component, resulting in a confidentiality impact only, as reflected by the CVSS 3.1 vector.

Affected Systems

Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is affected. No other versions or products are listed.

Risk and Exploitability

The CVSS base score of 5.5 indicates a moderate risk level. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker only needs to be logged into the infrastructure where Hyperion runs and possess low privileges, requiring no user interaction. The threat primarily concerns internal adversaries or compromised accounts who can exploit the misconfigured installation to read protected data.

Generated by OpenCVE AI on August 21, 2026 at 11:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Oracle patch or upgrade to a newer version of Oracle Hyperion Infrastructure Technology that removes this vulnerability.
  • Ensure that the service accounts running Hyperion have the minimum privileges required—implement least‑privilege and restrict local logon rights to only those users who need them.
  • Enable auditing on the Hyperion installation and configuration files to detect unauthorized changes or access attempts.

Generated by OpenCVE AI on August 21, 2026 at 11:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Title Local Vulnerability Allowing Unauthorized Data Access in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-200
CWE-284

Fri, 21 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Exploitable Local Privilege Escalation in Oracle Hyperion Installation and Configuration
Weaknesses CWE-284

Wed, 19 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Exploitable Local Privilege Escalation in Oracle Hyperion Installation and Configuration
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:25:40.196Z

Reserved: 2026-07-14T14:54:48.742Z

Link: CVE-2026-62573

cve-icon Vulnrichment

Updated: 2026-08-26T13:45:26.858Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:09.190

Modified: 2026-08-27T17:18:32.443

Link: CVE-2026-62573

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T11:45:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control