Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Oracle Hyperion Financial Reporting server component that permits an unauthenticated attacker to send HTTP requests to the application. The flaw requires human interaction from a third party to trigger the attack, but once activated it enables the attacker to modify, insert or delete data and to read portions of the system’s information, thereby compromising both data integrity and confidentiality.

Affected Systems

Oracle Corporation’s Hyperion Financial Reporting, version 11.2.25.0.000.

Risk and Exploitability

The CVSS v3.1 base score of 5.4 indicates moderate risk. The EPSS score is 0.00238, showing a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is unauthenticated network traffic over HTTP, but the need for user interaction from a non‑attacker makes successful exploitation more difficult in practice.

Generated by OpenCVE AI on August 21, 2026 at 06:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict HTTP access to Oracle Hyperion by limiting inbound connections to trusted internal networks and enforcing strict firewall rules.
  • Disable or secure any default or unused accounts that the application may expose over HTTP to reduce attack surface.
  • Monitor access logs for anomalous requests involving data manipulation or retrieval and investigate any suspicious activity promptly.
  • Report the vulnerability to Oracle or relevant vendors and await official guidance or a remedial patch.

Generated by OpenCVE AI on August 21, 2026 at 06:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP access allows data modification in Oracle Hyperion Financial Reporting
Weaknesses CWE-284

Wed, 19 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Manipulation via HTTP in Oracle Hyperion Financial Reporting
Weaknesses CWE-284

Wed, 19 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Manipulation via HTTP in Oracle Hyperion Financial Reporting
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Financial Reporting
CPEs cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Reporting
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Hyperion Financial Reporting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T19:54:23.053Z

Reserved: 2026-08-04T22:06:34.596Z

Link: CVE-2026-70766

cve-icon Vulnrichment

Updated: 2026-08-24T19:50:10.665Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:29.300

Modified: 2026-08-25T16:16:30.283

Link: CVE-2026-70766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T06:15:03Z

Weaknesses