Description
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L).
Published: 2026-08-18
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Hyperion Calculation Manager allows an unauthenticated attacker with network access via HTTP to create, delete, or modify critical data, read restricted subsets of data, and partially deny service. This results in integrity and availability impacts, as reflected by a CVSS v3.1 score of 7.0 with low confidentiality impact but high integrity and low availability impact, indicating a medium to high severity risk.

Affected Systems

Oracle Corporation’s Hyperion Calculation Manager, version 11.2.25.0.000, is affected by the flaw.

Risk and Exploitability

Exploitation requires only network connectivity to the HTTP endpoint of the Hyperion server and no credentials. The flaw is difficult to exploit remotely, making it a less practical threat for attackers with internet or internal network access; the EPSS score of less than 1% indicates a very low probability of exploitation. Nevertheless, the medium‑high CVSS base score, lack of authentication requirement, and absence of a KEV listing highlight a notable risk for organizations running this product.

Generated by OpenCVE AI on August 21, 2026 at 08:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s security patch or upgrade to a version of Hyperion Calculation Manager that fixes the authentication and authorization flaw.
  • Limit HTTP access to the Hyperion server by firewall rules or VPN, allowing only trusted systems or administrators to reach it.
  • Enable comprehensive auditing and monitoring for unauthorized data creation, deletion, or modification actions to detect any compromise.

Generated by OpenCVE AI on August 21, 2026 at 08:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Manipulation and Partial Denial of Service in Oracle Hyperion Calculation Manager

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Manipulation and Partial Denial of Service in Oracle Hyperion Calculation Manager
Weaknesses CWE-200
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L).
First Time appeared Oracle
Oracle hyperion Calculation Manager
CPEs cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Calculation Manager
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Oracle Hyperion Calculation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:14.341Z

Reserved: 2026-08-04T22:06:34.588Z

Link: CVE-2026-70676

cve-icon Vulnrichment

Updated: 2026-08-19T12:11:55.543Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:19.383

Modified: 2026-08-25T14:18:21.697

Link: CVE-2026-70676

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T09:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-285

    Improper Authorization