Description
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker with low privileges who can reach the Oracle Hyperion Calculation Manager over HTTP can tamper with, delete, or insert data and read restricted information. The vulnerability originates in the Security component and allows unauthorized updates, inserts, deletes, and partial reads. The CVSS 3.1 base score of 5.4 reflects moderate confidentiality and integrity impacts. The attack vector is at the network level, short attack complexity, and requires low privileges with no user interaction.

Affected Systems

Oracle Hyperion Calculation Manager, version 11.2.25.0.000.

Risk and Exploitability

The exploit is considered easily exploitable over a network, but the EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog, indicating limited current exploitation activity. The CVSS score indicates moderate risk, and the lack of user interaction makes it a realistic threat for attackers who can communicate with the affected instance.

Generated by OpenCVE AI on August 21, 2026 at 11:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch or upgrade to a non‑affected release of Oracle Hyperion Calculation Manager.
  • Limit HTTP access to the application by placing it behind a firewall or restricting it to trusted IP ranges.
  • Enforce strict role‑based access controls and review permissions to ensure only authorized users can update, insert, delete, or view data.

Generated by OpenCVE AI on August 21, 2026 at 11:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Read via Low-Privilege HTTP Access in Oracle Hyperion Calculation Manager
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Calculation Manager
CPEs cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Calculation Manager
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Hyperion Calculation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:24:54.955Z

Reserved: 2026-07-14T14:54:48.731Z

Link: CVE-2026-62441

cve-icon Vulnrichment

Updated: 2026-08-24T14:08:14.061Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:01.137

Modified: 2026-08-25T14:23:03.060

Link: CVE-2026-62441

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T11:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control