Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication and access‑control flaw in the Server component of Oracle Hyperion Financial Reporting 11.2.25.0.000 allows a low‑privileged attacker with network access via HTTP to obtain confidential reporting data and, in some cases, modify it. The vulnerability can lead to high confidentiality compromise and low integrity impact, enabling read or write access to sensitive financial information without valid credentials.

Affected Systems

Oracle Hyperion Financial Reporting version 11.2.25.0.000. All installations running the affected Server component are susceptible; no other versions are mentioned as impacted.

Risk and Exploitability

The CVSS base score of 6.3 indicates moderate confidentiality impact and low integrity impact. The EPSS score of < 1% reflects an extremely low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need network connectivity to the exposed HTTP interface and the cooperation of a user other than the attacker, suggesting a network‑based exploitation path with user interaction required. Given the potential for unauthorized data access and modification, timely remediation is recommended.

Generated by OpenCVE AI on August 21, 2026 at 08:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Oracle patch or update for Hyperion Financial Reporting 11.2.25.0.000 when released.
  • Limit external HTTP access to the Hyperion server to trusted internal networks or VPN‑only connections to reduce attack exposure.
  • Implement strict role‑based access controls within Hyperion and monitor for anomalous data access patterns.
  • Follow the official Oracle advisory for interim measures until a fix is released if no patch is currently available.

Generated by OpenCVE AI on August 21, 2026 at 08:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Easy‑to‑Exploit HTTP Access Control Flaw in Oracle Hyperion Financial Reporting
Weaknesses CWE-284

Fri, 21 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege HTTP in Hyperion Financial Reporting
Weaknesses CWE-284
CWE-640

Wed, 19 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege HTTP in Hyperion Financial Reporting
Weaknesses CWE-284
CWE-640

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Financial Reporting
CPEs cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Reporting
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Hyperion Financial Reporting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:24:29.374Z

Reserved: 2026-08-04T22:06:34.594Z

Link: CVE-2026-70753

cve-icon Vulnrichment

Updated: 2026-08-24T14:08:11.935Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:28.113

Modified: 2026-08-24T15:44:43.950

Link: CVE-2026-70753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T09:00:13Z

Weaknesses