CVE-2026-62535: High severity Oracle Oracle Hyperion Infrastructure Technology vulnerability
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An unauthenticated attacker with network access can exploit it. No user interaction or prior privileges are required, and exploitation is described as easy.
Which deployments are known to be affected?
The affected supported version identified is Oracle Hyperion Infrastructure Technology 11.2.25.0.000, specifically in its Installation and Configuration component.
What is the potential impact of a successful attack?
An attacker could gain unauthorized access to critical data or complete access to all data accessible through Oracle Hyperion Infrastructure Technology. The vulnerability can also significantly affect additional products because its scope changes.