Summary
CVE-2026-62501 is a high-severity vulnerability in the Common Events component of Oracle Hyperion Infrastructure Technology. It allows an unauthenticated attacker with network access via HTTP to compromise the affected system, with the potential for complete takeover. Oracle rates the flaw 8.1 (High) under CVSS v3.1.
Technical details
- Root cause: a flaw in the Common Events component of Oracle Hyperion Infrastructure Technology (specific technical root cause not detailed in the public record).
- Trigger conditions: exploitable only via HTTP network access; Oracle rates attack complexity as High, meaning successful exploitation depends on conditions outside the attacker’s control.
- Attack vector: Network (remote), requiring no authentication and no user interaction.
- Impact: successful exploitation can result in complete compromise of Oracle Hyperion Infrastructure Technology, affecting confidentiality, integrity, and availability at a High level.
Affected software
- Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000
Severity
- CVSS v3.1 Base Score: 8.1 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided by Oracle in the August 2026 Critical Patch Update (Critical Security Patch Update) for Oracle Hyperion Infrastructure Technology version 11.2.25.0.000.
- If patching cannot be applied immediately: restrict network access to Hyperion Infrastructure Technology interfaces to trusted internal networks only, and monitor exposed HTTP endpoints for anomalous activity until the patch is applied.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Oracle Enterprise Performance Management System Workspace, Fusion Edition

