Description
Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Profitability and Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Deployment component of Oracle Hyperion Profitability and Cost Management and allows an attacker who can reach the system via HTTP and possesses high privileges to gain full control of the application. Successful exploitation leads to compromise of confidentiality, integrity, and availability, effectively taking over the service. The weakness is identified as improper access control and weak permissions management, which enable privileged users to bypass critical security checks.

Affected Systems

Oracle Corporation's Hyperion Profitability and Cost Management product, version 11.2.25.0.000, is affected. No other vendors, products, or versions are identified in the CVE listing.

Risk and Exploitability

The CVSS 3.1 base score of 7.2 reflects high severity with impacts on confidentiality, integrity, and availability. The attack vector indicates network access (AV:N), low complexity (AC:L), and high privileges (PR:H), meaning an attacker with the appropriate credentials can fully compromise the application. The EPSS score of less than 1% suggests that widespread exploitation is unlikely at this time, and the vulnerability is not listed in the CISA KEV catalog, so no mandated actions are required by CISA.

Generated by OpenCVE AI on August 25, 2026 at 21:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle's CSPU Aug 2026 advisory for an official patch or upgrade that addresses the Deployment component flaw.
  • Limit HTTP access to Hyperion to trusted IP addresses or internal networks, enforcing least privilege at the network layer.
  • Enable detailed logging of authentication and deployment operations, and regularly monitor logs for unauthorized activity.

Generated by OpenCVE AI on August 25, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title High Privilege HTTP Exploit Compromises Oracle Hyperion Profitability and Cost Management

Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Exploit Allows Full Takeover of Oracle Hyperion Profitability and Cost Management
Weaknesses CWE-272

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 21 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Exploit Allows Full Takeover of Oracle Hyperion Profitability and Cost Management
Weaknesses CWE-272

Wed, 19 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Exploit in Oracle Hyperion Profitability and Cost Management Deployment Component
Weaknesses CWE-269
CWE-284
CWE-862

Wed, 19 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Exploit in Oracle Hyperion Profitability and Cost Management Deployment Component
Weaknesses CWE-269
CWE-284
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Profitability and Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Profitability And Cost Management
CPEs cpe:2.3:a:oracle:hyperion_profitability_and_cost_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Profitability And Cost Management
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Profitability And Cost Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:10:13.868Z

Reserved: 2026-08-04T22:06:34.593Z

Link: CVE-2026-70735

cve-icon Vulnrichment

Updated: 2026-08-25T15:06:25.375Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:26.213

Modified: 2026-08-27T14:09:35.243

Link: CVE-2026-70735

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:30:06Z

Weaknesses