Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Hyperion Financial Reporting version 11.2.25.0.000 contains a server‑side access‑control flaw that permits an unauthenticated attacker with network access via HTTP to take full control of the application, compromising confidentiality, integrity, and availability. Based on the description, it is inferred that an attacker can execute arbitrary code on the server; the vulnerability is classified as CWE‑284 (Improper Access Control).

Affected Systems

The affected product is Oracle Corporation’s Hyperion Financial Reporting server, specifically release 11.2.25.0.000. No other vendors, products, or versions are listed in the CNA data, so the risk is confined to this version and component.

Risk and Exploitability

The CVSS 3.1 base score of 9.8 indicates critical severity; the network‑based attack requires only unauthenticated HTTP access, making exploitation trivially achievable in theory. The EPSS score of < 1% suggests a low current exploitation probability, and the vulnerability is not yet listed in CISA’s KEV catalog. Nevertheless, the combination of a high impact, open attack vector and absence of authentication warrants immediate action.

Generated by OpenCVE AI on August 26, 2026 at 03:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for Hyperion Financial Reporting version 11.2.25.0.000, as detailed in the Oracle Security Alert for August 2026.
  • Restrict external HTTP access to the Hyperion server to a limited set of trusted IP ranges, effectively blocking unauthorized traffic.
  • Monitor application logs and network traffic for anomalous activity indicative of exploitation attempts, and configure alerts for suspicious patterns.

Generated by OpenCVE AI on August 26, 2026 at 03:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Enabling Full Compromise in Oracle Hyperion Financial Reporting

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 21 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Hyperion Financial Reporting
Weaknesses CWE-287

Wed, 19 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Hyperion Financial Reporting
Weaknesses CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Reporting
CPEs cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Reporting
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Reporting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T16:36:46.135Z

Reserved: 2026-08-04T22:06:34.593Z

Link: CVE-2026-70740

cve-icon Vulnrichment

Updated: 2026-08-25T15:41:08.672Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:26.780

Modified: 2026-08-25T19:05:27.973

Link: CVE-2026-70740

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T03:45:03Z

Weaknesses