Sceawere

Vulnerability Detail

CVE-2026-70964UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Infrastructure Technology Flaw

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Infrastructure Technology
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data.
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. While the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-08-18T21:17:54.957Z",
  "pubdate": "2026-08-18T21:17:54.957Z",
  "executiveSummary": "An unauthenticated or low-privileged network-based vulnerability affects the Oracle Hyperion Infrastructure Technology product, specifically within the Installation and Configuration component in version 11.2.25.0.000.\nThis vulnerability is classified as difficult to exploit due to high attack complexity requirements, but successful exploitation allows a low-privileged attacker with network access via HTTP to compromise the targeted system.\nThe security flaw exhibits a scope change, meaning that successful attacks against Oracle Hyperion Infrastructure Technology can significantly impact additional integrated or dependent products beyond the primary administrative boundary.\nThe primary impacts of this vulnerability include unauthorized creation, deletion, or modification of critical data, alongside unauthorized or complete access to all accessible data within the Oracle Hyperion Infrastructure Technology ecosystem.\nThe associated CVSS 3.1 base score is 8.2, reflecting severe confidentiality and integrity impacts while maintaining no availability disruption.\nRisk implications remain high given the potential for data compromise across multiple collateral software products, necessitating prompt administrative oversight and defensive hardening.",
  "technicalDetails": "The vulnerability resides within the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000.\nThe attack vector is network-based (AV:N), allowing remote adversaries capable of routing HTTP traffic to target the exposed service endpoints.\nExploitation requires low privileges (PR:L), meaning the adversary must possess valid user credentials within the system context, and no user interaction (UI:N) is mandated to successfully execute the attack chain.\nThe attack complexity is rated as high (AC:H), indicating that successful exploitation requires specific pre-conditions, precise timing, race conditions, or specialized configuration states to be met by the threat actor.\nThe vulnerability features a scope change (S:C), signifying that the authorization boundary of the vulnerable Oracle Hyperion Infrastructure Technology component is transcended, allowing malicious actions to propagate and impact additional collateral products operating within the same administrative domain or network topology.\nThe step-by-step attack flow begins with an authenticated low-privileged user establishing an HTTP-based network connection to the vulnerable Installation and Configuration interface.\nThe attacker submits a specially crafted request designed to bypass intended logical constraints or access control boundaries within the component.\nDue to insufficient input validation or flawed authorization checks during processing, the payload alters system state or exposes sensitive data stores outside the intended privilege level.\nPost-exploitation impacts involve severe confidentiality (C:H) and integrity (I:H) compromises, granting the attacker capabilities to read critical data assets and perform unauthorized insertions, modifications, or deletions of sensitive records across Oracle Hyperion Infrastructure Technology and cross-product scopes, while availability (A:N) remains unaffected."
}
CVE-2026-70964: Oracle Hyperion Infrastructure Technology Flaw (HIGH Severity, CVSS: 8.2) - Sceawere