Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The issue is an authentication and access control flaw that allows low‑privileged users with HTTP access to obtain confidential data and, in some cases, modify it. The flaw resides in the Server component of Oracle Hyperion Financial Reporting 11.2.25.0.000. Because the vulnerability is readily exploitable, an adversary can gain unauthorized read and possibly write access to the reporting database, exposing sensitive financial information.

Affected Systems

The vulnerable software is Oracle Hyperion Financial Reporting, version 11.2.25.0.000. All installations of this product running the affected server component are susceptible. No other versions were indicated as affected.

Risk and Exploitability

The CVSS base score of 6.3 reflects moderate confidentiality impact and low integrity impact. There is no EPSS score, and the issue is not cataloged in KEV. Attackers require network connectivity to the HTTP interface and a user interface interaction from a party other than the attacker. The vectors suggest a network‑based exploitation in an environment where HTTP traffic is accessible to potential attackers. The lack of automated exploitation evidence makes the likelihood lower, yet the reach granted is significant, warranting timely remediation.

Generated by OpenCVE AI on August 19, 2026 at 01:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch that fixes the access control flaw in Hyperion Financial Reporting 11.2.25.0.000.
  • Limit HTTP access to the Hyperion server to trusted internal networks or VPN‑only connections to reduce the attack surface.
  • Enforce strict role‑based access controls and monitor for anomalous data‑access patterns.

Generated by OpenCVE AI on August 19, 2026 at 01:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege HTTP in Hyperion Financial Reporting
Weaknesses CWE-284
CWE-640

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Financial Reporting
CPEs cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Reporting
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Hyperion Financial Reporting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:01:22.420Z

Reserved: 2026-08-04T22:06:34.594Z

Link: CVE-2026-70753

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:28.113

Modified: 2026-08-18T21:17:28.113

Link: CVE-2026-70753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T02:00:05Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password