Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Repository component of Oracle Hyperion Financial Reporting. An attacker with only network connectivity to the HTTP service can exploit the flaw without authentication to perform unauthorized insert, update, or delete operations on the application data and read protected information. The weakness is classified as CWE-306, indicating an authentication bypass vulnerability. The impact on confidentiality is moderate and on integrity is moderate, as the attacker can both introduce harmful data and modify existing records.

Affected Systems

Oracle Corporation’s Hyperion Financial Reporting, version 11.2.25.0.000 is the only version explicitly listed as affected. No other product or version information is provided.

Risk and Exploitability

The CVSS base score of 6.5 reflects moderate severity with low attack complexity, no authentication, no user interaction, and a shared scope, impacting confidentiality and integrity. The EPSS score is less than 1%, indicating a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog, suggesting no active exploitation. The likely attack vector is unauthenticated HTTP access to the Enterprise Hyperion Financial Reporting Repository component, enabling an attacker to modify, insert, delete, or read data without credentials.

Generated by OpenCVE AI on August 21, 2026 at 15:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict HTTP access to the application using network segmentation or firewall rules to limit exposure to trusted hosts.
  • Monitor application logs for anomalous write or read operations and investigate any suspicious activity promptly.
  • Check for vendor security patches or advisories related to this CVE.

Generated by OpenCVE AI on August 21, 2026 at 15:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle hyperion Financial Management

Fri, 21 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification and Retrieval in Oracle Hyperion Financial Reporting 11.2.25.0.000

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Financial Reporting
CPEs cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Reporting
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Hyperion Financial Management Hyperion Financial Reporting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T18:08:45.784Z

Reserved: 2026-07-08T15:51:55.578Z

Link: CVE-2026-60682

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:39.083

Modified: 2026-08-21T16:38:51.983

Link: CVE-2026-60682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:00:15Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function