Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Vulnerability in Oracle Hyperion Infrastructure Technology lies in the installation and configuration component, allowing an unauthenticated attacker who can reach the system over an HTTP network connection to compromise the service. This vulnerability corresponds to CWE‑601, an open redirect weakness. The exploit requires a separate human actor—someone other than the attacker—to interact with the system, after which the attacker can achieve full takeover of the Oracle Hyperion instance. The impact spans confidentiality, integrity and availability, as identified by the CVSS score of 9.6, and the vector indicates a scope change, meaning privileges can be increased within the same realm.

Affected Systems

Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000, a product of Oracle Corporation. The vulnerability applies to this specific build; no other versions are listed as affected.

Risk and Exploitability

With a CVSS Base Score of 9.6 the vulnerability is classified as Critical. The EPSS score of <1% indicates a very low exploitation probability, and it is not listed in the CISA Known Exploited Vulnerabilities catalog, but the high score and the fact that it requires only unauthenticated network access over HTTP raise the likelihood that attackers will target the affected infrastructure. Successful exploitation would give the attacker full control of the Hyperion service, potentially affecting other connected products due to the scope change. The dependency on external human interaction may reduce the immediacy of exploitation, yet once a user interacts, compromise is typically straightforward.

Generated by OpenCVE AI on August 22, 2026 at 08:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for Hyperion Infrastructure Technology 11.2.25.0.000, which removes the open redirect weakness identified as CWE‑601.
  • Restrict HTTP access to the Hyperion service using firewalls or access‑control lists to only trusted networks or hosts.
  • Review and delete any default or insecure credentials in Hyperion configuration files, and enforce strong authentication for all administrative accounts.

Generated by OpenCVE AI on August 22, 2026 at 08:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Takeover of Oracle Hyperion Infrastructure Technology

Sat, 22 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploit for Unauthenticated Takeover in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-16
CWE-287

Sat, 22 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploit for Unauthenticated Takeover in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-16
CWE-287

Thu, 20 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Vulnerability in Oracle Hyperion Infrastructure Technology Enabling Service Takeover
Weaknesses CWE-862

Wed, 19 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Vulnerability in Oracle Hyperion Infrastructure Technology Enabling Service Takeover
Weaknesses CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T03:29:25.905Z

Reserved: 2026-08-04T22:06:34.608Z

Link: CVE-2026-70958

cve-icon Vulnrichment

Updated: 2026-08-22T03:29:20.955Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:54.273

Modified: 2026-08-25T16:08:35.253

Link: CVE-2026-70958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T08:15:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')