Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).
Published: 2026-08-18
Score: 3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the installation and configuration process of Oracle Hyperion Infrastructure Technology 11.2.25.0.000 gives a high‑privileged local attacker the ability to modify, insert, or delete data that the application can access, and to trigger a partial denial of service. The vulnerability does not allow remote code execution or privilege escalation beyond what the attacker already possesses, but it undermines the confidentiality, integrity, and availability of the application’s data and the service’s uptime.

Affected Systems

The affected product is Oracle Hyperion Infrastructure Technology from Oracle Corporation. Only version 11.2.25.0.000 is listed as vulnerable. No other versions are mentioned, and the weakness is tied to the installation and configuration component.

Risk and Exploitability

The CVSS v3.1 base score is 3.0, reflecting low overall severity with modest integrity and availability impacts. EPSS is not available, indicating no publicly known high likelihood of exploitation. The flaw requires local physical or virtual console access and high‑privilege credentials to the host where the product runs, meaning a targeted insider or attacker with elevated local rights. The vulnerability is not in the CISA KEV catalog, so there is no evidence of ongoing exploitation in the wild. Nonetheless, any environment running the affected release should treat this as a notable risk when local high‑privileged accounts are present on the same infrastructure.

Generated by OpenCVE AI on August 19, 2026 at 11:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security alerts or product release notes for a patch or upgrade applicable to Hyperion Infrastructure Technology 11.2.25.0.000 and apply it as soon as possible.
  • If a fix is not yet available, enforce least privilege for local accounts that can log onto the host hosting the application; remove or restrict any unnecessary local administrator privileges.
  • Consider isolating the Hyperion service on a dedicated, hardened host and apply network segmentation so only required services can reach it.
  • Implement monitoring for unexpected data modifications and symptoms of service disruption, and regularly review logs for suspicious activity.

Generated by OpenCVE AI on August 19, 2026 at 11:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Attack Enables Unauthorized Data Modification and Partial Denial of Service in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284
CWE-400

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:15.018Z

Reserved: 2026-07-14T14:54:48.743Z

Link: CVE-2026-62583

cve-icon Vulnrichment

Updated: 2026-08-19T12:12:11.439Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:10.430

Modified: 2026-08-24T16:13:16.520

Link: CVE-2026-62583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:00:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-400

    Uncontrolled Resource Consumption