Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the installation and configuration component of Oracle Hyperion Infrastructure Technology and enables a low‑privileged network attacker to create, delete or modify critical data and to gain unauthorized access to all accessible data. The flaw is an improper access control weakness that results in confidentiality and integrity loss for the affected system.

Affected Systems

Oracle Corporation’s Hyperion Infrastructure Technology product, version 11.2.25.0.000, is affected. No other versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity with significant confidentiality and integrity impact. The attack vector is network (HTTP), with low attack complexity and privilege requirements. Although the EPSS score is below 1%, which shows a low current exploitation probability, the ease of exploitation via HTTP and the availability of a low‑privileged attacker make the risk noteworthy. The vulnerability is not listed in the CISA KEV catalog, but the potential for wide‑scale data breach warrants rapid remediation.

Generated by OpenCVE AI on August 22, 2026 at 08:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for Hyperion Infrastructure Technology 11.2.25.0.000 as detailed in the Oracle security alert.
  • Restrict HTTP access to the Hyperion instance by limiting inbound traffic to trusted IP ranges or VPN connections.
  • Review and enforce role‑based permissions on Hyperion to ensure only authorized users can create, delete or modify data.

Generated by OpenCVE AI on August 22, 2026 at 08:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privilege HTTP Exploit in Oracle Hyperion Infrastructure Technology

Sat, 22 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privilege HTTP Exploit in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-285

Sat, 22 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 20 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284

Wed, 19 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T03:28:22.474Z

Reserved: 2026-08-04T22:06:34.608Z

Link: CVE-2026-70957

cve-icon Vulnrichment

Updated: 2026-08-22T03:28:17.264Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:54.153

Modified: 2026-08-25T16:09:04.203

Link: CVE-2026-70957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T08:15:03Z

Weaknesses