Sceawere
Vulnerability Detail
CVE-2026-70958UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Infrastructure Technology Takeover Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Infrastructure Technology
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-08-18T21:17:54.273Z",
"pubdate": "2026-08-18T21:17:54.273Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Installation and Configuration component of the Oracle Hyperion Infrastructure Technology product, specifically affecting version 11.2.25.0.000.\nThe vulnerability allows an unauthenticated attacker with network access via HTTP to execute a remote attack that can result in the complete takeover of the affected product.\nSuccessful exploitation of this flaw requires human interaction from a user other than the attacker.\nDue to a change in the security scope, successful attacks may significantly impact additional products beyond the primary vulnerable component.\nThe vulnerability carries a maximum CVSS 3.1 Base Score of 9.6, indicating critical severity with high impacts across confidentiality, integrity, and availability.\nThe combination of unauthenticated network access, low attack complexity, and high downstream impact poses severe risk to enterprise environments utilizing the affected Oracle Hyperion version.",
"technicalDetails": "The vulnerability resides in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000.\nNetwork exposure is enabled via the HTTP protocol, allowing remote unauthenticated threat actors to interact with the vulnerable service.\nThe attack vector does not require prior authentication or elevated privileges, lowering the barrier to entry for potential adversaries.\nExploitation requires human interaction, meaning an external user other than the attacker must perform a specific action, such as interacting with a maliciously crafted link or interface element, to facilitate the attack chain.\nThe attack flow involves sending crafted HTTP requests that leverage weaknesses in the Installation and Configuration component, crossing security boundaries due to a scope change (S:C).\nPost-exploitation impact includes a complete takeover of the Oracle Hyperion Infrastructure Technology instance, alongside significant security implications for additional downstream or integrated products.\nThe resulting impact compromises all three pillars of information security: confidentiality, integrity, and availability, allowing unauthorized data access, system modification, and service disruption."
}