Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is found in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000. It can be exploited by a low privileged user that is logged on to the infrastructure where the product runs. Successful exploitation would allow that user to compromise the product and read critical data stored or managed by Oracle Hyperion Infrastructure Technology. The description clearly states that unauthorized access to critical data may result from a successful attack, indicating that the confidentiality of the data is the primary impact.

Affected Systems

Oracle Corporation’s Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000. Only this specific version is listed as affected.

Risk and Exploitability

The CVSS 3.1 score of 4.7 reflects a medium severity with a local attack vector, high access complexity, low privilege, no user interaction, and scope unchanged. Confidentiality is impacted while integrity and availability are unaffected. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. According to the description, the attack requires the attacker to be logged into the environment and to have low privilege on the host; the vulnerability is described as difficult to exploit, which suggests that successful attacks are not trivial but still possible if necessary conditions are met.

Generated by OpenCVE AI on August 19, 2026 at 11:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Hyperion Infrastructure Technology to a version that contains the fixed code, or apply any vendor patch that addresses the installation and configuration flaw.
  • Restrict local logon rights to the minimum set of trusted accounts and enforce the principle of least privilege for users that interact with the product.
  • Disable the vulnerable installation and configuration component if it is not required for operations.
  • If no patch is immediately available, monitor system activity for signs of unauthorized data access and review security logs regularly to detect potential exploitation attempts.

Generated by OpenCVE AI on August 19, 2026 at 11:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Exploit Allows Unauthorized Data Access in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:25:32.489Z

Reserved: 2026-07-14T14:54:48.742Z

Link: CVE-2026-62575

cve-icon Vulnrichment

Updated: 2026-08-26T13:45:28.959Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:09.467

Modified: 2026-08-27T17:17:56.443

Link: CVE-2026-62575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T11:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control