Description
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker who is only lightly privileged and has network access through HTTP to take over the Oracle Hyperion Calculation Manager. The impact is complete loss of confidentiality, integrity, and availability for that instance, and, because the exploit can change the attack scope, it may also affect other products that interact with the calculation manager.

Affected Systems

Oracle Hyperion Calculation Manager version 11.2.25.0.000 is affected.

Risk and Exploitability

The CVSS score of 9.9 places this flaw in the high‑to‑critical range. An attacker would need only low privileged network access via HTTP and requires no user interaction to exploit it. The EPSS score of <1% indicates that real‑world exploitation is currently very low but still possible. The vulnerability is not listed in the CISA KEV catalog, but the vector shows that the attacker can change scope and possibly compromise additional related products after initial takeover.

Generated by OpenCVE AI on August 21, 2026 at 20:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for version 11.2.25.0.000 or later
  • Restrict HTTP access to Oracle Hyperion Calculation Manager to authorized IP ranges using firewalls or security groups
  • Implement network segmentation and monitoring to detect lateral movement from the calculation manager to other systems

Generated by OpenCVE AI on August 21, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Calculation Manager Remote Code Execution via Low-Privilege HTTP Access

Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Compromises Oracle Hyperion Calculation Manager
Weaknesses CWE-285
CWE-287

Fri, 21 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 21 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Compromises Oracle Hyperion Calculation Manager
Weaknesses CWE-285
CWE-287

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP attack enables full compromise of Oracle Hyperion Calculation Manager
Weaknesses CWE-284

Wed, 19 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP attack enables full compromise of Oracle Hyperion Calculation Manager
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Calculation Manager
CPEs cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Calculation Manager
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Calculation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T16:48:19.250Z

Reserved: 2026-07-08T15:52:20.740Z

Link: CVE-2026-61206

cve-icon Vulnrichment

Updated: 2026-08-21T13:41:18.879Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:55.020

Modified: 2026-08-25T14:22:41.877

Link: CVE-2026-61206

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses