Summary
CVE-2026-62535 is a high-severity vulnerability in Oracle Hyperion Infrastructure Technology, specifically within the Installation and Configuration component. It allows an unauthenticated attacker with network access via multiple protocols to compromise the system and gain unauthorized access to critical data. The flaw carries a CVSS v3.1 base score of 8.6 and was disclosed as part of Oracle’s August 2026 Critical Security Patch Update.
Technical details
- Root cause: A flaw in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology.
- Trigger conditions: No authentication or user interaction is required; the vulnerability is described as "easily exploitable."
- Attack vector: Network-based, reachable via multiple protocols (AV:N, AC:L).
- Impact: Results in unauthorized access to critical data, with the potential for complete access to all data accessible to Oracle Hyperion Infrastructure Technology. Oracle notes the vulnerability may also significantly impact additional, connected products. Confidentiality impact is High; Integrity and Availability are not affected. The CVSS Scope metric is Changed (S:C), indicating impact beyond the vulnerable component itself.
Affected software
- Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Security Patch Update released in August 2026, which contains the fix for CVE-2026-62535 and other Oracle Hyperion vulnerabilities.
- If patching cannot be performed immediately: Restrict network access to Oracle Hyperion Infrastructure Technology components to trusted internal networks only, and monitor exposed management/configuration interfaces for unusual access attempts until the patch can be applied.

