Description
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Calculation Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful exploitation requires interaction from a person other than the attacker, yet results in the attacker being able to create, delete, or modify critical data or gain complete access to all accessible data. The impact is a high confidentiality and integrity compromise, with a CVSS 3.1 Base Score of 8.1.

Affected Systems

Oracle Hyperion Calculation Manager, version 11.2.25.0.000, in use by Oracle Corporation.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity, while the EPSS score is not available; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network-based via HTTP, requiring a user to interact with the system that initiates the attack. Because the exploitation is unauthenticated, the barrier for entry is low, but the need for a separate human to trigger the attack raises the required complexity. However, once the attacker obtains unauthorized modify or view permissions, the potential for data loss, corruption, or disclosure is substantial.

Generated by OpenCVE AI on August 21, 2026 at 11:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch from the August 2026 security alert (https://www.oracle.com/security-alerts/cspuaug2026.html).
  • Restrict HTTP access to the Hyperion service to a trusted internal network or VPN, blocking external inbound connections.
  • Configure the calculation manager to enforce strict role‑based access controls and remove unused accounts; enable logging and monitor for unauthorized creation, deletion, or modification of data.

Generated by OpenCVE AI on August 21, 2026 at 11:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTP Access Enables Data Modification in Oracle Hyperion Calculation Manager
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Calculation Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Calculation Manager
CPEs cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Calculation Manager
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Calculation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T15:52:49.775Z

Reserved: 2026-07-08T15:52:20.745Z

Link: CVE-2026-61281

cve-icon Vulnrichment

Updated: 2026-08-21T15:50:31.264Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:57.683

Modified: 2026-08-25T14:22:37.427

Link: CVE-2026-61281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:00:11Z

Weaknesses