Description
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is in the Security component of Oracle Hyperion Calculation Manager and is identified as a CWE‑284 (Broken Access Control) weakness. It permits an attacker with low privileges who can reach the application over HTTP to take control of the server, compromising confidentiality, integrity, and availability. The flaw has a CVSS v3.1 score of 8.8, indicating a high‑impact weakness that allows the attacker to achieve a full takeover.

Affected Systems

Oracle Hyperion Calculation Manager version 11.2.25.0.000 is the only version identified as affected. The issue applies to all installations of this product on supported platforms.

Risk and Exploitability

The CVSS base score of 8.8 reflects a high‑impact vulnerability that requires only low complexity and low privileges. It can be exploited over the public network using HTTP without user interaction. The EPSS score of < 1% shows a very low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalogue. A low‑privileged attacker can compromise the system by sending a crafted HTTP request to the vulnerable service.

Generated by OpenCVE AI on August 21, 2026 at 21:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for Oracle Hyperion Calculation Manager version 11.2.25.0.000, available from the Oracle Security Alerts website.
  • Restrict HTTP access to the Hyperion server to trusted IP ranges by configuring firewall rules or requiring VPN access.
  • Enforce strong authentication and, where feasible, enable multi‑factor authentication for the HTTP interface to reduce the risk of credential misuse.
  • Monitor Hyperion logs for anomalous access patterns and apply rate limiting to mitigate automated attack attempts.

Generated by OpenCVE AI on August 21, 2026 at 21:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title HTTP Remote Takeover from Low-Privilege User in Oracle Hyperion Calculation Manager

Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Low Privileged HTTP‑Based Compromise of Oracle Hyperion Calculation Manager
Weaknesses CWE-287

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Low Privileged HTTP‑Based Compromise of Oracle Hyperion Calculation Manager
Weaknesses CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Calculation Manager
CPEs cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Calculation Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Calculation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T15:46:52.160Z

Reserved: 2026-07-08T15:52:20.744Z

Link: CVE-2026-61276

cve-icon Vulnrichment

Updated: 2026-08-21T15:46:30.513Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:57.570

Modified: 2026-08-25T14:25:24.197

Link: CVE-2026-61276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:30:17Z

Weaknesses