Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the server component of Oracle Hyperion Financial Reporting, where an unauthenticated attacker can send crafted HTTP requests that enable unauthorized creation, modification, or deletion of critical data and full access to all accessible data. This represents a breach of confidentiality and integrity and is a CWE‑284 (Improper Access Control) weakness.

Affected Systems

Oracle Corporation’s Hyperion Financial Reporting, version 11.2.25.0.000, is the only known affected release. Deployments of the server component that have not been patched beyond this version are at risk.

Risk and Exploitability

The CVSS v3.1 base score of 8.1 indicates high severity, and the EPSS score of 0.352% indicates low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack requires network access over HTTP without authentication, but also requires a human interaction from a user other than the attacker, limiting the attacker’s ability to exploit the flaw solo. Environments that expose the Hyperion server to the internet or rely on shared user credentials face a high risk.

Generated by OpenCVE AI on August 21, 2026 at 08:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade beyond version 11.2.25.0.000 to eliminate the vulnerability.
  • Restrict inbound HTTP traffic to the Hyperion server to trusted IP ranges or enforce VPN access, thereby shrinking the attack surface.
  • Configure application‑level access controls to enforce user permissions and mitigate the CWE‑284 weakness.
  • Monitor web logs for abnormal request patterns, especially attempts to create, modify, or delete data, and block or quarantine offending IPs.

Generated by OpenCVE AI on August 21, 2026 at 08:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enabling Unauthorized Data Modification in Oracle Hyperion Financial Reporting
Weaknesses CWE-284

Fri, 21 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access in Oracle Hyperion Financial Reporting Allows Data Compromise
Weaknesses CWE-284

Wed, 19 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access in Oracle Hyperion Financial Reporting Allows Data Compromise
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Financial Reporting
CPEs cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Reporting
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Financial Reporting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:09:39.723Z

Reserved: 2026-08-04T22:06:34.594Z

Link: CVE-2026-70746

cve-icon Vulnrichment

Updated: 2026-08-25T15:06:31.714Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:27.450

Modified: 2026-08-25T16:16:52.753

Link: CVE-2026-70746

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T08:45:12Z

Weaknesses