SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-62541 2026-08-18

CVE-2026-62541: Critical Unauthenticated Takeover in Oracle Hyperion Infrastructure Technology

"Oracle disclosed a CVSS 9.8 flaw in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology 11.2.25.0.000 that lets an unauthenticated attacker take over the product over HTTP."

Oracle disclosed a CVSS 9.8 flaw in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology 11.2.25.0.000 that lets an unauthenticated attacker take over the product over HTTP.

What Is It

CVE-2026-62541 is a critical vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion, specifically in the Installation and Configuration component. Per Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the affected product. Successful attacks result in full takeover of Oracle Hyperion Infrastructure Technology.

The CVSS 3.1 base score is 9.8 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, an exploitability subscore of 3.9 and impact subscore of 5.9.

Why It Matters

Every barrier that normally slows an attacker is absent here: no credentials, no user interaction, low attack complexity, and network-reachable over HTTP. The impact is high across confidentiality, integrity, and availability, and Oracle describes the outcome as takeover rather than partial compromise.

Hyperion Infrastructure Technology underpins Oracle's enterprise performance management stack. Depending on how a given environment is deployed and segmented, compromise of this layer could put the financial planning and consolidation applications running on top of it at risk as well; the supplied data does not establish the blast radius beyond the affected product itself. Any internet-facing or broadly reachable instance should be treated as a priority.

There is no CISA KEV entry for CVE-2026-62541 in the supplied data, so active exploitation is not confirmed at this time. That is not a reason to defer patching given the exploitability profile.

What's Vulnerable

No CPE match data was published with the record, so version coverage beyond 11.2.25.0.000 is not established in the source material.

Patch Status

The vulnerability was reported by Oracle ([email protected]) and published on 2026-08-18, with NVD status listed as "Received"; meaning NVD analysis is still pending.

Oracle ships Critical Patch Updates on a fixed quarterly cadence, January, April, July and October, so there is no August 2026 CPU. A CVE published on 2026-08-18 falls between the July and October releases: administrators should check whether a fix for Hyperion Infrastructure Technology already shipped in the July 2026 Critical Patch Update, and otherwise expect remediation in the October 2026 CPU or in an out-of-cycle Security Alert, which Oracle reserves for severe issues that cannot wait for the next quarterly window. Confirm the fix listed against Hyperion Infrastructure Technology in whichever advisory carries it before applying it to affected 11.2.25.0.000 deployments. No specific required-action deadline is present in the supplied data.

Sources