CVE-2026-62580: Low severity Oracle Oracle Hyperion Calculation Manager vulnerability
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 2.6 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
Which deployments should be prioritized for review?
Prioritize Oracle Hyperion Calculation Manager deployments running the identified affected supported version, 11.2.25.0.000, particularly where low-privileged users could access the physical network segment serving the host.
What level of attacker access is required?
An attacker must already have low-privileged access and access to the physical communication segment attached to the hardware running Calculation Manager. User interaction is not required, and exploitation is rated as difficult.
What is the expected impact if exploitation succeeds?
A successful attacker may gain unauthorized ability to update, insert, or delete some data accessible through Oracle Hyperion Calculation Manager. The stated impact is limited to integrity; no confidentiality or availability impact is specified.