Vulnerability in Oracle Hyperion Infrastructure Technology Lifecycle Management
CVE-2026-35244

5.2MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 April 2026

What is CVE-2026-35244?

An exploitable vulnerability has been identified in the Oracle Hyperion Infrastructure Technology, specifically within the Lifecycle Management component. This issue allows an attacker with high privileges and network access via HTTP to compromise the system. While successful exploitation requires human interaction from someone other than the attacker, it can lead to unauthorized creation, deletion, or modification of critical data. Additionally, attackers may gain unauthorized read access to certain datasets. This vulnerability highlights the importance of safeguarding sensitive data within the Oracle Hyperion environment.

Affected Version(s)

Oracle Hyperion Infrastructure Technology 11.2.24.0.000

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.