Summary
CVE-2026-62457 is a critical, easily exploitable vulnerability in the Common Events component of Oracle Hyperion Infrastructure Technology, part of the Oracle Hyperion Enterprise Performance Management (EPM) product line. It allows an unauthenticated, remote attacker with only network access over HTTP to fully compromise the affected product. Oracle rates this vulnerability CVSS 3.1 base score 9.8 (Critical), with high impact to confidentiality, integrity, and availability.
Technical details
- Root cause: a flaw in the Common Events component of Oracle Hyperion Infrastructure Technology.
- Trigger conditions: exploitation does not require any authentication or user interaction.
- Attack vector: remote exploitation over HTTP/network access; attack complexity is rated low.
- Impact: successful exploitation can result in complete takeover of the Oracle Hyperion Infrastructure Technology installation, with high impact to confidentiality, integrity, and availability.
Affected software
- Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000 (supported release affected).
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: apply the fix provided in Oracle’s August 2026 Critical Patch Update for Oracle Hyperion Infrastructure Technology version 11.2.25.0.000.
- If patching cannot be applied immediately, restrict network access to Hyperion Infrastructure Technology interfaces (e.g., via firewall rules or VPN-only access) to reduce exposure to unauthenticated remote attackers until the patch is applied.

