Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Reporting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-08-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Server component of Oracle Hyperion Financial Reporting and permits an unauthenticated attacker with network access via HTTP to alter or add data and to read data that the application already exposes. It requires human interaction from a user other than the attacker. Once that condition is met, the exploit can modify or read restricted data, impacting the confidentiality and integrity of reports and financial information.

Affected Systems

The only explicitly affected product is Oracle Hyperion Financial Reporting version 11.2.25.0.000; no other sub‑products or versions are identified as vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 6.1 reflects moderate severity with low authentication and local user interface requirements. Human interaction is required, which lowers the overall exploitation likelihood. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, indicating limited publicly observed exploitation. Nonetheless, the potential for unauthorized data changes and scope expansion warrants attention.

Generated by OpenCVE AI on August 21, 2026 at 09:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle security patch for Hyperion Financial Reporting 11.2.25.0.000 to address the vulnerability.
  • Restrict HTTP access to the Hyperion server to trusted IP ranges or networks with strict firewall rules to reduce the attack surface.
  • Enforce strict access control and input validation to prevent unauthorized data modification and disclosure.

Generated by OpenCVE AI on August 21, 2026 at 09:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification and Disclosure in Oracle Hyperion Financial Reporting
Weaknesses CWE-284

Fri, 21 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification and Disclosure in Oracle Hyperion Financial Reporting
Weaknesses CWE-20
CWE-200
CWE-284

Wed, 19 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification and Disclosure in Oracle Hyperion Financial Reporting
Weaknesses CWE-20
CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Reporting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Financial Reporting
CPEs cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Reporting
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Hyperion Financial Reporting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:24:16.861Z

Reserved: 2026-08-04T22:06:34.596Z

Link: CVE-2026-70768

cve-icon Vulnrichment

Updated: 2026-08-24T14:08:10.792Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:29.540

Modified: 2026-08-24T15:44:17.330

Link: CVE-2026-70768

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T09:30:09Z

Weaknesses