Sceawere

Vulnerability Detail

CVE-2026-70967UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Infrastructure Technology
Attack Type
Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data.
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-18T21:17:55.307Z",
  "pubdate": "2026-08-18T21:17:55.307Z",
  "executiveSummary": "A security vulnerability has been identified within the Oracle Hyperion Infrastructure Technology product, specifically residing in the Installation and Configuration component. The affected supported version is 11.2.25.0.000. This security flaw is categorized as an easily exploitable vulnerability that allows a low-privileged threat actor with local interactive logon capabilities to the underlying infrastructure where Oracle Hyperion Infrastructure Technology executes to successfully compromise the application architecture. Successful exploitation of this vulnerability can lead to unauthorized creation, deletion, or modification access to critical data, as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. The vulnerability yields a CVSS 3.1 Base Score of 7.1 with high impacts to confidentiality and integrity, while availability remains unaffected. The attack vector is local (AV:L), attack complexity is low (AC:L), privileges required are low (PR:L), user interaction is not required (UI:N), and the scope remains unchanged (S:U).",
  "technicalDetails": "The vulnerability exists within the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. The root cause stems from improper access controls or insecure handling of local resources and configuration files during execution, allowing low-privileged authenticated local users to manipulate or access restricted system assets. The exploitation vector requires the attacker to have pre-existing low-privileged shell or interactive logon access to the host operating system hosting the Oracle Hyperion Infrastructure Technology instance. Because the attack vector is local (AV:L) with low attack complexity (AC:L) and low required privileges (PR:L), an authenticated local user can execute arbitrary commands, scripts, or direct file manipulations against vulnerable installation and configuration routines. The attack flow initiates with the low-privileged user authenticating to the local infrastructure. Subsequently, the attacker leverages the insecure permissions or flawed logic within the Oracle Hyperion Infrastructure Technology Installation and Configuration component to bypass standard authorization boundaries. This allows the actor to escalate privileges regarding data access or perform unauthorized data tampering. The payload behavior involves unauthorized read, write, and delete operations targeted against critical data repositories and accessible data structures managed by the software. Post-exploitation impacts are strictly confined to the compromise of data confidentiality and integrity, resulting in severe data exposure or corruption without inducing a denial-of-service condition on the host system."
}
CVE-2026-70967: Oracle Hyperion Privilege Escalation Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere