Description
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the security component of Oracle Hyperion Calculation Manager (version 11.2.25.0.000) allows an unauthenticated attacker who can reach the system over HTTP to read a limited subset of data that is normally protected by the application. The flaw does not affect integrity or availability and is classified as a confidentiality‑only weakness.

Affected Systems

The affected product is Oracle Hyperion Calculation Manager from Oracle Corporation. The specific affected version is 11.2.25.0.000; no other releases are listed in the available vendor information.

Risk and Exploitability

The CVSS base score of 3.7 reflects a low‑to‑moderate severity and indicates that only confidentiality is impacted. The EPSS score of <1% indicates a very low likelihood of exploitation, and the vulnerability is not in the CISA KEV catalog, suggesting that current exploit activity is unknown. The likely attack vector is an unauthenticated HTTP connection to the Hyperion web interface; the attacker merely needs network access and does not require any credentials or privileged configuration. Successful exploitation would reveal a subset of data, but no privilege escalation or denial of service is possible.

Generated by OpenCVE AI on August 25, 2026 at 21:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Oracle security advisory at https://www.oracle.com/security-alerts/cspuaug2026.html for a patch or upgrade once a fix is released.
  • Restrict inbound HTTP traffic to the Hyperion web interface using firewalls, ACLs, or VPN restrictions to limit exposure to trusted sources.
  • Apply network segmentation or internal routing controls so that only authenticated internal hosts can reach the Hyperion service, thereby reducing the surface for unauthenticated requests.

Generated by OpenCVE AI on August 25, 2026 at 21:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via HTTP to Oracle Hyperion Calculation Manager
Weaknesses CWE-200

Tue, 25 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 19 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via HTTP to Oracle Hyperion Calculation Manager
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Calculation Manager
CPEs cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Calculation Manager
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Hyperion Calculation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T16:22:43.300Z

Reserved: 2026-08-04T22:06:34.589Z

Link: CVE-2026-70682

cve-icon Vulnrichment

Updated: 2026-08-25T16:20:23.243Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:20.073

Modified: 2026-08-25T17:18:13.870

Link: CVE-2026-70682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:15:13Z

Weaknesses