Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Hyperion Infrastructure Technology 11.2.25.0.000 allows an unauthenticated attacker with network access over TLS to bypass authentication and gain unauthorized access to critical data, including the ability to update, insert or delete records. The flaw is an authentication bypass, classified as an improper access control weakness. Successful exploitation can lead to unauthorized disclosure of confidential information and unauthorized modification of data, posing a moderate confidentiality and integrity risk to the affected system.

Affected Systems

Affected systems are all installations of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 deployed by Oracle Corporation. Only this version is confirmed to be impacted; other versions are not known to be vulnerable at this time.

Risk and Exploitability

The CVSS base score of 6.5 indicates a medium severity vulnerability that requires network exposure and no authentication. The EPSS score of <1% indicates a very low exploitation probability, and the lack of a CISA KEV listing suggests no widely observed exploitation yet. However, because the attack path requires only TLS network connectivity and no privileged credentials, the potential for exploitation remains significant, especially in environments where Hyperion is directly exposed to untrusted networks.

Generated by OpenCVE AI on August 21, 2026 at 11:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Oracle patch or upgrade to a supported version that addresses this access control flaw.
  • Restrict TLS traffic to the Hyperion service by applying firewall rules or network segmentation so that only trusted IP ranges can reach the application.
  • Enable and monitor detailed access logs on Hyperion to detect and investigate any unauthorized data access or modification attempts.

Generated by OpenCVE AI on August 21, 2026 at 11:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in Oracle Hyperion Infrastructure Technology via TLS
Weaknesses CWE-284
CWE-287

Fri, 21 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated TLS Access Enables Data Breach in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284

Wed, 19 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated TLS Access Enables Data Breach in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T17:34:45.745Z

Reserved: 2026-07-14T14:54:48.742Z

Link: CVE-2026-62576

cve-icon Vulnrichment

Updated: 2026-08-26T17:28:21.776Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:09.587

Modified: 2026-08-27T17:17:33.707

Link: CVE-2026-62576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T11:45:04Z

Weaknesses