Summary
CVE-2026-62543 is a critical vulnerability in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology (part of Oracle Hyperion). It allows an unauthenticated, remote attacker with network access via HTTP to fully compromise and take over the affected system. Oracle rates it 9.8 (Critical) under CVSS v3.1.
Technical details
- Root cause lies in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology.
- Oracle describes the flaw as "easily exploitable," requiring no authentication and no user interaction.
- Attack vector is the network, via HTTP, meaning exploitation can be attempted directly against internet-exposed Hyperion instances.
- Successful exploitation results in takeover of Oracle Hyperion Infrastructure Technology, with high impact to confidentiality, integrity, and availability.
- Oracle has not published a detailed technical root-cause writeup (e.g., specific injection or deserialization mechanism) beyond the advisory summary.
Affected software
- Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000 (Oracle Hyperion product family).
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Patch Update for Oracle Hyperion Infrastructure Technology 11.2.25.0.000.
- If patching cannot be performed immediately: restrict network/HTTP access to Hyperion Infrastructure Technology components to trusted internal networks only, and place the service behind a firewall or VPN until the patch is applied, since Oracle has not published an alternative workaround.
- Monitor Hyperion-facing systems for anomalous HTTP requests as an interim compensating control.
How IONIX identifies potentially affected assets
IONIX matches the following signal against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Oracle Enterprise Performance Management System Workspace, Fusion Edition

