Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Hyperion Financial Reporting 11.2.25.0.000 allows an unauthenticated attacker with network access via HTTP to achieve a full system takeover, resulting in complete compromise of confidentiality, integrity, and availability. The CVSS 3.1 base score of 8.1 reflects these severe impacts.

Affected Systems

Oracle Corporation’s Hyperion Financial Reporting product, version 11.2.25.0.000, is affected. No other versions or components are currently listed as vulnerable.

Risk and Exploitability

The vulnerability can be exploited remotely over HTTP without authentication or special privileges. While the EPSS score is not available, the high CVSS score indicates significant risk, and the absence of a KEV listing does not lower the potential threat. Attackers could send crafted HTTP requests to the server to trigger code execution and gain full control of the application server.

Generated by OpenCVE AI on August 19, 2026 at 01:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in August 2026 for Hyperion Financial Reporting 11.2.25.0.000 to fix the unauthenticated remote takeover flaw.
  • Restrict inbound HTTP traffic to the Hyperion server by configuring firewall rules or a VPN to limit access to trusted networks.
  • If the patch cannot be applied immediately, disable all unused HTTP endpoints on the server and enforce TLS to block plain‑text connections, mitigating the risk of remote exploitation.

Generated by OpenCVE AI on August 19, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Takeover in Oracle Hyperion Financial Reporting 11.2.25.0.000
Weaknesses CWE-94

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Reporting
CPEs cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Reporting
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Reporting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:01:19.800Z

Reserved: 2026-08-04T22:06:34.594Z

Link: CVE-2026-70744

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:27.227

Modified: 2026-08-18T21:17:27.227

Link: CVE-2026-70744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T02:00:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')