cve-2026-62553
MEDIUM CVSS 5.5 opencveVulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
- Published
- 2026-08-18 21:17 UTC
- Last Modified
- 2026-08-25
CVSS details not available.
No product information available.
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
mitre | ||
| 3.1 | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
nvd | ||
| 3.1 | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
opencve |
No references available.
{
"cve": "CVE-2026-62553",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "generic",
"value": "11.2.25.0.000"
}
}
],
"enrichment": {
"confidence": 100.0,
"confidence_source": "inferred",
"scores": [
{
"score": 100.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "Oracle Hyperion Infrastructure Technology",
"source": "cna",
"vendor": "Oracle Corporation"
},
"product": "hyperion_infrastructure_technology",
"vendor": "oracle"
}
],
"created": "2026-08-19T01:15:12.516543+00:00",
"title": "Local Privilege Access Reads Confidential Data in Oracle Hyperion Infrastructure",
"updated": "2026-08-26T06:00:12.842129+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$hyperion_infrastructure_technology"
]
},
"epss": {
"score": 0.00154
},
"mitre": {
"cpes": [
"cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:00:29.392000+00:00",
"description": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 5.5,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/62xxx/CVE-2026-62553.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-25T18:03:33.275000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$hyperion_infrastructure_technology"
],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:17:07.727000+00:00",
"description": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 5.5,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-62553.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-25T18:17:57.520000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$hyperion_infrastructure_technology"
],
"weaknesses": [
"CWE-284",
"NVD-CWE-noinfo"
]
},
"opencve": {
"changes": [
{
"created": "2026-08-18T21:15:00+00:00",
"data": [
{
"details": {
"new": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"old": null
},
"type": "description"
},
{
"details": [
"oracle",
"oracle$PRODUCT$hyperion_infrastructure_technology"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle",
"oracle$PRODUCT$hyperion_infrastructure_technology"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 5.5,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "a2dcc14a-ddea-43ae-b338-29132370386b"
},
{
"created": "2026-08-19T01:30:00+00:00",
"data": [
{
"details": {
"new": "Local Privileged Access Allows Confidential Data Exposure in Oracle Hyperion Infrastructure Technology",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-284"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "ccf122aa-6223-4df6-9744-0e23bfb99187"
},
{
"created": "2026-08-21T10:00:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Local Privileged Access Allows Confidential Data Exposure in Oracle Hyperion Infrastructure Technology"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-284"
]
},
"type": "weaknesses"
}
],
"id": "a34605c1-d07f-4122-8ebc-ed1c2af19dfb"
},
{
"created": "2026-08-21T12:30:00+00:00",
"data": [
{
"details": {
"new": "Local Privileged User Information Disclosure in Oracle Hyperion Infrastructure Technology",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-200",
"CWE-276"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "7afebd1c-a79e-4a84-8564-f4dd2e6013f6"
},
{
"created": "2026-08-25T16:30:00+00:00",
"data": [
{
"details": {
"added": [
"NVD-CWE-noinfo"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "d37af20a-1cfb-409c-809a-6c172ae8549f"
},
{
"created": "2026-08-25T18:30:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-284"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "3d8385c5-212c-4129-9248-c310ddab47e1"
},
{
"created": "2026-08-26T04:45:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Local Privileged User Information Disclosure in Oracle Hyperion Infrastructure Technology"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-200",
"CWE-276"
]
},
"type": "weaknesses"
}
],
"id": "27f5c3ec-ba48-4923-9a1a-c33b7cd8388b"
},
{
"created": "2026-08-26T06:15:00+00:00",
"data": [
{
"details": {
"new": "Local Privilege Access Reads Confidential Data in Oracle Hyperion Infrastructure",
"old": null
},
"type": "title"
}
],
"id": "a95bdf48-84ee-43c5-a459-7077f36ed3bb"
}
],
"cpes": {
"data": [
"cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.25.0.000:*:*:*:*:*:*:*"
],
"providers": [
"mitre",
"nvd"
]
},
"created": {
"data": "2026-08-18T21:00:29.392000+00:00",
"provider": "mitre"
},
"description": {
"data": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 5.5,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00154
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "Local Privilege Access Reads Confidential Data in Oracle Hyperion Infrastructure",
"provider": "enrichment"
},
"updated": {
"data": "2026-08-26T06:00:12.842129+00:00",
"provider": "enrichment"
},
"vendors": {
"data": [
"oracle",
"oracle$PRODUCT$hyperion_infrastructure_technology"
],
"providers": [
"mitre",
"nvd",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-284",
"NVD-CWE-noinfo"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-08-18T21:00:29.392000+00:00",
"description": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"references": [],
"title": null,
"updated": "2026-08-25T17:56:40.687000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/62xxx/CVE-2026-62553.json",
"weaknesses": [
"CWE-284"
]
}
}