Sceawere
Vulnerability Detail
CVE-2026-70966UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Infrastructure Technology Takeover
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Infrastructure Technology
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-18T21:17:55.190Z",
"pubdate": "2026-08-18T21:17:55.190Z",
"executiveSummary": "A remotely exploitable vulnerability exists within the Installation and Configuration component of the Oracle Hyperion Infrastructure Technology product, specifically affecting version 11.2.25.0.000. This security flaw allows an authenticated attacker with low privileges and network access via the HTTP protocol to execute a successful compromise of the target system. The vulnerability presents severe risk implications, as successful exploitation results in the complete takeover of the affected Oracle Hyperion Infrastructure Technology instance, impacting confidentiality, integrity, and availability with a CVSS 3.1 Base Score of 8.8. The attack vector is network-based with low attack complexity, requiring no user interaction, but necessitates low-privileged network access to initiate the exploit sequence against the vulnerable product.",
"technicalDetails": "The vulnerability resides in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. The root cause stems from insufficient validation and handling of incoming HTTP requests processed by the vulnerable component. Because the affected software exposes administrative or configuration interfaces over the network, it fails to properly enforce authorization boundaries and input sanitization for low-privileged authenticated sessions.\nThe attack flow begins when an adversary leverages valid low-privileged credentials to establish a network connection via HTTP to the vulnerable Oracle Hyperion Infrastructure Technology endpoint. The attacker transmits a maliciously crafted HTTP payload targeting the Installation and Configuration component. Due to inadequate security controls within the request processing pipeline, the application improperly handles the input, leading to unauthorized execution or privilege escalation.\nExploitation does not require user interaction and exhibits low attack complexity, allowing a threat actor to rapidly operationalize the attack once network access and low-level credentials are acquired. The payload behavior facilitates the circumvention of security controls embedded within the installation and configuration workflows.\nPost-exploitation impact is critical, resulting in the total takeover of the Oracle Hyperion Infrastructure Technology environment. This grants the attacker full control over the application stack, enabling unauthorized data access and modification, disruption of availability, and potential lateral movement within the underlying network architecture."
}