SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-62457 2026-08-18

CVE-2026-62457: Critical Unauthenticated Takeover in Oracle Hyperion Infrastructure Technology

"Oracle disclosed a CVSS 9.8 flaw in the Common Events component of Oracle Hyperion Infrastructure Technology that lets an unauthenticated attacker take over the product over HTTP."

Oracle disclosed a CVSS 9.8 flaw in the Common Events component of Oracle Hyperion Infrastructure Technology that lets an unauthenticated attacker take over the product over HTTP.

What Is It

CVE-2026-62457 is a critical vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion, specifically in the Common Events component. Per Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise the affected product. Successful exploitation results in full takeover of Oracle Hyperion Infrastructure Technology.

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low attack complexity, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability.

Why It Matters

Every precondition an attacker would normally need is absent here: no credentials, no user interaction, no local access. An attacker who can reach the HTTP interface can attempt exploitation directly, and the outcome is not partial data disclosure but takeover of the Hyperion Infrastructure Technology instance.

The record was published on 2026-08-18 and is currently in NVD status "Received," meaning NVD analysis is not yet complete. CVE-2026-62457 does not appear in CISA's Known Exploited Vulnerabilities catalog (https://www.cisa.gov/known-exploited-vulnerabilities-catalog), so active exploitation is not confirmed at this time; the risk here is driven by the exploitability profile, not by observed in-the-wild activity.

What's Vulnerable

Oracle lists 11.2.25.0.000 as the supported version affected. No CPE entries were present in the supplied NVD record.

Patch Status

Oracle ships security fixes through its quarterly Critical Patch Update cycle, which is released in January, April, July, and October; there is no August CPU. The supplied source material does not identify which CPU carries the fix for CVE-2026-62457, nor a fixed version number or separate required-action deadline. Administrators should check the most recent CPU advisory (July 2026) and the next scheduled CPU (October 2026) for the applicable patch for 11.2.25.0.000. Because the flaw is reachable over HTTP without authentication, restricting network exposure of Hyperion interfaces to trusted networks reduces attack surface while patching is scheduled.

Sources