Sceawere

Vulnerability Detail

CVE-2026-70959UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Infrastructure Technology Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Infrastructure Technology
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Infrastructure Technology.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-18T21:17:54.387Z",
  "pubdate": "2026-08-18T21:17:54.387Z",
  "executiveSummary": "An easily exploitable vulnerability affects the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion, specifically within the Installation and Configuration component. The affected supported version is 11.2.25.0.000. This security flaw enables a low-privileged attacker with network access via HTTP to compromise the targeted system.\nSuccessful exploitation of this vulnerability results in significant integrity and availability impacts. Specifically, attackers gain unauthorized capabilities to perform creation, deletion, or modification actions on critical data or all data accessible to Oracle Hyperion Infrastructure Technology. Additionally, successful attacks can cause a hang or a frequently repeatable complete denial of service (DoS) of the application.\nThe vulnerability carries a CVSS 3.1 Base Score of 8.1 with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H, indicating network attack vector, low attack complexity, low privileges required, and no user interaction required. The risk implications are severe for enterprise environments relying on the confidentiality, integrity, and operational uptime of their Oracle Hyperion deployments, necessitating prompt attention and defense-in-depth measures.",
  "technicalDetails": "The vulnerability resides within the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. The underlying root cause involves improper input validation, access control enforcement, or resource management handling within administrative or configuration endpoints exposed via HTTP over the network.\nExploitation of this flaw requires network connectivity to the target service and low privileges within the Oracle Hyperion Infrastructure Technology environment. Because the attack vector is network-based (AV:N) and requires low attack complexity (AC:L) with no user interaction (UI:N), an authenticated user with minimal access rights can interact directly with vulnerable HTTP interfaces.\nThe attack flow proceeds as follows: First, the low-privileged attacker establishes an HTTP connection to the vulnerable endpoints exposed by the Installation and Configuration component. Second, the attacker submits crafted HTTP requests designed to bypass inadequate authorization or validation controls. Third, the application processes these malicious payloads, allowing the attacker to execute unauthorized data modification, creation, or deletion routines against critical enterprise data repositories. Alternatively or concurrently, the attacker can submit requests engineered to exhaust system resources or trigger exception conditions, leading to a hang or a frequently repeatable complete denial of service (complete DOS).\nPost-exploitation impact focuses heavily on integrity and availability. While confidentiality is not directly impacted according to the CVSS vector (C:N), the ability to alter critical application data (I:H) and disrupt core operational availability (A:H) compromises the reliability and trustworthiness of the entire Oracle Hyperion Infrastructure Technology environment."
}
CVE-2026-70959: Oracle Hyperion Infrastructure Technology Vulnerability (HIGH Severity, CVSS: 8.1) - Sceawere