Sceawere

Vulnerability Detail

CVE-2026-70961UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Infrastructure Technology Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Infrastructure Technology
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-08-18T21:17:54.620Z",
  "pubdate": "2026-08-18T21:17:54.620Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. This security flaw allows unauthenticated remote attackers with network access via HTTP to compromise the affected software, provided there is successful human interaction from a user other than the attacker. Due to a scope change, successful exploitation has the potential to significantly impact additional products beyond the primary vulnerable system. The impact of a successful attack includes unauthorized read access to a subset of accessible data, as well as unauthorized update, insert, or delete access to some accessible data within Oracle Hyperion Infrastructure Technology. The vulnerability yields a CVSS 3.1 Base Score of 6.1 with impacts restricted to confidentiality and integrity, leaving availability unaffected. Given the remote vector and lack of authentication requirements, organizations utilizing the specified version face moderate risk and must rely on mandatory user interaction and network defenses as mitigating factors until official patches or updates are applied.",
  "technicalDetails": "The vulnerability resides in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology, specifically affecting supported version 11.2.25.0.000. The security flaw is exposed via the HTTP protocol, allowing network-adjacent or remote unauthenticated threat actors to interact with the vulnerable application endpoints. Exploitation requires zero privileges (PR:N) and low attack complexity (AC:L), making the vector highly accessible to external entities provided the prerequisite attack conditions are met. A critical operational requirement for successful exploitation is human interaction (UI:R), meaning an authenticated or visiting user must be manipulated into performing a specific action, such as clicking a malicious link or interacting with a crafted web payload supplied by the attacker. The attack vector leverages a scope change (S:C), indicating that the vulnerability allows an attacker to impact resources and security domains beyond the administrative boundaries of the vulnerable Oracle Hyperion Infrastructure Technology component itself, potentially cascading into integrated or co-located enterprise products. The post-exploitation impact encompasses unauthorized data disclosure affecting a subset of confidential information (C:L) and unauthorized data modification capabilities, including the ability to execute insert, update, or delete operations on sensitive data stores (I:L). The exploitation flow typically proceeds with the attacker crafting a malicious HTTP-based payload designed to exploit the input handling or configuration routines of the installation module. Upon delivering this payload to the target application via network requests, the attacker induces the required human interaction from the victim. Once the user interacts with the malicious content, the application processes the untrusted input within the context of the user session or vulnerable service, bypassing expected access controls. This facilitates unauthorized data access and modification across the application boundary, fulfilling the confidentiality and integrity breach criteria defined by the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)."
}
CVE-2026-70961: Oracle Hyperion Infrastructure Technology Vulnerability (MEDIUM Severity, CVSS: 6.1) - Sceawere