Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Hyperion Infrastructure Technology is vulnerable to an access control flaw that allows attackers with low‑privilege credentials who can reach the service over HTTP to create, delete or modify critical data and to trigger the application to hang or crash repeatedly, thereby compromising data integrity and system availability.

Affected Systems

Only the Oracle Hyperion Infrastructure Technology product version 11.2.25.0.000 from Oracle Corporation is affected.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 reflects significant integrity and availability impacts, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability remotely over HTTP without special privileges, making exposed installations at appreciable risk.

Generated by OpenCVE AI on August 22, 2026 at 07:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's latest security patch for Hyperion Infrastructure Technology 11.2.25.0.000 immediately
  • Limit the service's HTTP access to trusted hosts or internal networks by configuring firewall rules or network segmentation
  • Continuously monitor application logs and system metrics for unauthorized data changes or abnormal crash patterns, and investigate any suspicious activity promptly

Generated by OpenCVE AI on August 22, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Control Flaw Allows Data Modification and Service Crash in Oracle Hyperion

Sat, 22 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Access Control Flaw in Oracle Hyperion Infrastructure Technology Enables Unauthorized Data Modification and Denial of Service
Weaknesses CWE-287

Sat, 22 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Access Control Flaw in Oracle Hyperion Infrastructure Technology Enables Unauthorized Data Modification and Denial of Service
Weaknesses CWE-287

Thu, 20 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Vulnerability Enabling Data Tampering and Denial of Service in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284
CWE-639

Wed, 19 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Vulnerability Enabling Data Tampering and Denial of Service in Oracle Hyperion Infrastructure Technology
Weaknesses CWE-284
CWE-639

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Infrastructure Technology
CPEs cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Infrastructure Technology
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Oracle Hyperion Infrastructure Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T03:30:27.900Z

Reserved: 2026-08-04T22:06:34.608Z

Link: CVE-2026-70959

cve-icon Vulnrichment

Updated: 2026-08-22T03:30:22.733Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:54.387

Modified: 2026-08-25T16:07:36.420

Link: CVE-2026-70959

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T08:00:13Z

Weaknesses