Description
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Hyperion Calculation Manager version 11.2.25.0.000 permits an attacker who is already logged on to the infrastructure where the product runs to compromise the software. The weakness enables unauthorized access to confidential data and, because the impact scope changes, could extend to full control over all data accessible by the product. The vulnerability is an access‑control deficiency that can lead to data disclosure.

Affected Systems

The affected vendor is Oracle Corporation and the impacted product is Oracle Hyperion Calculation Manager. The specific version affected is 11.2.25.0.000. No other products or versions are listed, though the issue may also affect any other products that interact with Hyperion CM.

Risk and Exploitability

The CVSS v3.1 base score of 7.1 indicates a high severity for confidentiality impacts. The exploitability vector shows local access with no privilege separation and no user interaction, implying that an attacker who has any local foothold can exploit the flaw. The EPSS score of <1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the high CVSS base score and local nature mean that an attacker who gains local access can still compromise the system.

Generated by OpenCVE AI on August 25, 2026 at 16:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy Oracle’s official patch or upgrade to a version where the vulnerability is resolved
  • Limit physical and network access to the servers hosting Hyperion CM and enforce strong authentication controls for local logins
  • Review and apply the principle of least privilege to all accounts that can access the Hyperion CM installation, ensuring no unnecessary administrative rights

Generated by OpenCVE AI on August 25, 2026 at 16:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Potential System Control via Local Access in Oracle Hyperion Calculation Manager

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Fri, 21 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Access to Oracle Hyperion Calculation Manager 11.2.25.0.000

Wed, 19 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Access to Oracle Hyperion Calculation Manager 11.2.25.0.000
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. While the vulnerability is in Oracle Hyperion Calculation Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Calculation Manager
CPEs cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Calculation Manager
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Calculation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:56:48.727Z

Reserved: 2026-08-04T22:06:34.591Z

Link: CVE-2026-70705

cve-icon Vulnrichment

Updated: 2026-08-25T15:56:42.748Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:22.687

Modified: 2026-08-25T16:17:18.513

Link: CVE-2026-70705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T17:00:04Z

Weaknesses