CVE-2026-62572: Medium severity Oracle Hyperion Infrastructure Technology vulnerability
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
An attacker must already have a low-privileged account and be able to log on to the infrastructure where Oracle Hyperion Infrastructure Technology runs. The CVSS vector identifies the attack as local and requires no user interaction.
Which version is identified as affected?
The affected supported version is 11.2.25.0.000.
What is the potential impact of a successful attack?
A successful attacker can gain unauthorized access to critical data or complete access to data accessible to Oracle Hyperion Infrastructure Technology. The vulnerability may also significantly affect additional products because its scope changes.