Sceawere
Vulnerability Detail
CVE-2026-70967UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Privilege Escalation Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Infrastructure Technology
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-08-18T21:17:55.307Z",
"pubdate": "2026-08-18T21:17:55.307Z",
"executiveSummary": "A security vulnerability has been identified within the Oracle Hyperion Infrastructure Technology product, specifically residing in the Installation and Configuration component. The affected supported version is 11.2.25.0.000. This security flaw is categorized as an easily exploitable vulnerability that allows a low-privileged threat actor with local interactive logon capabilities to the underlying infrastructure where Oracle Hyperion Infrastructure Technology executes to successfully compromise the application architecture. Successful exploitation of this vulnerability can lead to unauthorized creation, deletion, or modification access to critical data, as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. The vulnerability yields a CVSS 3.1 Base Score of 7.1 with high impacts to confidentiality and integrity, while availability remains unaffected. The attack vector is local (AV:L), attack complexity is low (AC:L), privileges required are low (PR:L), user interaction is not required (UI:N), and the scope remains unchanged (S:U).",
"technicalDetails": "The vulnerability exists within the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. The root cause stems from improper access controls or insecure handling of local resources and configuration files during execution, allowing low-privileged authenticated local users to manipulate or access restricted system assets. The exploitation vector requires the attacker to have pre-existing low-privileged shell or interactive logon access to the host operating system hosting the Oracle Hyperion Infrastructure Technology instance. Because the attack vector is local (AV:L) with low attack complexity (AC:L) and low required privileges (PR:L), an authenticated local user can execute arbitrary commands, scripts, or direct file manipulations against vulnerable installation and configuration routines. The attack flow initiates with the low-privileged user authenticating to the local infrastructure. Subsequently, the attacker leverages the insecure permissions or flawed logic within the Oracle Hyperion Infrastructure Technology Installation and Configuration component to bypass standard authorization boundaries. This allows the actor to escalate privileges regarding data access or perform unauthorized data tampering. The payload behavior involves unauthorized read, write, and delete operations targeted against critical data repositories and accessible data structures managed by the software. Post-exploitation impacts are strictly confined to the compromise of data confidentiality and integrity, resulting in severe data exposure or corruption without inducing a denial-of-service condition on the host system."
}