Summary
CVE-2026-62544 is a critical vulnerability in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology, affecting version 11.2.25.0.000. The flaw allows an unauthenticated, remote attacker with network access via HTTP to fully compromise the affected system, impacting confidentiality, integrity, and availability. Oracle rates this vulnerability as easily exploitable and disclosed it as part of its August 2026 Critical Patch Update.
Technical details
- Root cause: A flaw in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology.
- Trigger conditions: No authentication or user interaction is required; the attacker only needs network access to the target over HTTP.
- Attack vector: Network (remote), low attack complexity.
- Impact: Successful exploitation can result in complete takeover of the Oracle Hyperion Infrastructure Technology system, with high impact to confidentiality, integrity, and availability.
Affected software
- Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update for August 2026, which contains the fix for CVE-2026-62544, to all affected Oracle Hyperion Infrastructure Technology deployments running version 11.2.25.0.000.
- If immediate patching is not possible: Restrict network access to Oracle Hyperion Infrastructure Technology interfaces (e.g., via firewall rules, VPN, or network segmentation) to reduce exposure to unauthenticated HTTP-based attacks until the patch can be applied.

