SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-62463 2026-08-18

Oracle Hyperion Infrastructure Technology Hit With Critical Scope-Changing Flaw (CVE-2026-62463)

"Oracle has disclosed a critical (CVSS 9.6) vulnerability in the Lifecycle Management component of Oracle Hyperion Infrastructure Technology that lets a low-privileged network attacker read and modify critical data, and…"

Oracle has disclosed a critical (CVSS 9.6) vulnerability in the Lifecycle Management component of Oracle Hyperion Infrastructure Technology that lets a low-privileged network attacker read and modify critical data, and potentially reach beyond the vulnerable product itself.

What Is It

CVE-2026-62463 is a vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion, specifically in the Lifecycle Management component. Oracle describes it as easily exploitable: an attacker with low privileges and network access over HTTP can compromise the product with no user interaction required.

The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N, yielding a base score of 9.6 (CRITICAL). Successful exploitation results in unauthorized creation, deletion, or modification of critical data, plus unauthorized read access to critical data or complete access to all data accessible to Oracle Hyperion Infrastructure Technology. Availability impact is rated none.

Why It Matters

The scope-changed flag (S:C) is what pushes this from serious to critical. Oracle notes explicitly that while the vulnerability resides in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products. Depending on how a given deployment is integrated, a foothold here may not stay contained to the vulnerable component.

The bar for entry is low: no user interaction, low attack complexity, network-reachable over HTTP, and only low privileges required. Any authenticated account with minimal rights is a viable launch point against the confidentiality and integrity of the full Hyperion data set.

CISA KEV data was not supplied for this CVE, so there is no confirmation of active exploitation at this time.

What's Vulnerable

This is the only supported version listed as affected in the NVD record.

Patch Status

The CVE was published 2026-08-18 with a vulnerability status of "Received," meaning NVD enrichment is still pending. The record's vendor reference is cited as an "August 2026 Critical Patch Update" advisory, but that attribution does not hold up: Oracle ships Critical Patch Updates on a fixed quarterly cycle (January, April, July, and October), so there is no August 2026 edition, and the cited URL is malformed and does not resolve. Until the NVD entry is enriched, treat the specific advisory pointer as unverified; the fix is expected to be carried by the nearest scheduled Critical Patch Update, which administrators should confirm against Oracle's advisory index directly.

Administrators running 11.2.25.0.000 should locate the current Critical Patch Update for Hyperion via the Oracle security alerts index below and apply the associated patch.

Sources