Summary
CVE-2026-62541 is a critical vulnerability in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000. It allows an unauthenticated, remote attacker to compromise the affected system completely, receiving a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: a flaw in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology.
- Trigger conditions: the vulnerability is described by Oracle as "easily exploitable" and requires no authentication or user interaction to trigger.
- Attack vector: exploitable remotely over a network via the HTTP protocol.
- Impact: successful exploitation results in complete compromise/takeover of the Oracle Hyperion Infrastructure Technology system, with high impact to confidentiality, integrity, and availability.
Affected software
- Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: apply the Oracle Critical Patch Update that addresses CVE-2026-62541 for Oracle Hyperion Infrastructure Technology and upgrade beyond version 11.2.25.0.000, per Oracle’s official security alert.
- If a patch cannot be applied immediately: restrict network access to Hyperion Infrastructure Technology components, ensure they are not directly exposed to the internet, and monitor HTTP traffic to these systems for anomalous or exploit-pattern requests until the patch can be deployed.

