Sceawere

Vulnerability Detail

CVE-2026-70958UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Infrastructure Technology Takeover Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Infrastructure Technology
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-08-18T21:17:54.273Z",
  "pubdate": "2026-08-18T21:17:54.273Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Installation and Configuration component of the Oracle Hyperion Infrastructure Technology product, specifically affecting version 11.2.25.0.000.\nThe vulnerability allows an unauthenticated attacker with network access via HTTP to execute a remote attack that can result in the complete takeover of the affected product.\nSuccessful exploitation of this flaw requires human interaction from a user other than the attacker.\nDue to a change in the security scope, successful attacks may significantly impact additional products beyond the primary vulnerable component.\nThe vulnerability carries a maximum CVSS 3.1 Base Score of 9.6, indicating critical severity with high impacts across confidentiality, integrity, and availability.\nThe combination of unauthenticated network access, low attack complexity, and high downstream impact poses severe risk to enterprise environments utilizing the affected Oracle Hyperion version.",
  "technicalDetails": "The vulnerability resides in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000.\nNetwork exposure is enabled via the HTTP protocol, allowing remote unauthenticated threat actors to interact with the vulnerable service.\nThe attack vector does not require prior authentication or elevated privileges, lowering the barrier to entry for potential adversaries.\nExploitation requires human interaction, meaning an external user other than the attacker must perform a specific action, such as interacting with a maliciously crafted link or interface element, to facilitate the attack chain.\nThe attack flow involves sending crafted HTTP requests that leverage weaknesses in the Installation and Configuration component, crossing security boundaries due to a scope change (S:C).\nPost-exploitation impact includes a complete takeover of the Oracle Hyperion Infrastructure Technology instance, alongside significant security implications for additional downstream or integrated products.\nThe resulting impact compromises all three pillars of information security: confidentiality, integrity, and availability, allowing unauthorized data access, system modification, and service disruption."
}
CVE-2026-70958: Oracle Hyperion Infrastructure Technology Takeover Vulnerability (CRITICAL Severity, CVSS: 9.6) - Sceawere