Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 2.6 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N).
Published: 2026-08-18
Score: 2.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Oracle Hyperion Financial Reporting server component and permits a low‑privileged attacker with network access over HTTP to perform unauthorized update, insert, or delete operations on data that is accessible to the application. This condition leads to an integrity impact, allowing the attacker to alter the trustworthiness of reported financial information. The weakness is characterized as an access control flaw (CWE‑284).

Affected Systems

Oracle Hyperion Financial Reporting version 11.2.25.0.000, deployed under Oracle Corporation.

Risk and Exploitability

The CVSS 3.1 base score is 2.6, indicating a low severity risk, and the EPSS score is less than 1 %. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote over HTTP and requires an attacker with low privileges; successful exploitation also demands human interaction from a user other than the attacker, implying the need to persuade or rely on an internal user to trigger a data modification action.

Generated by OpenCVE AI on August 24, 2026 at 21:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch for Oracle Hyperion Financial Reporting when it becomes available.
  • Restrict HTTP access to the Hyperion server to trusted network segments and legitimate user groups.
  • Enforce strict role‑based access controls and review permissions for data modification operations.

Generated by OpenCVE AI on August 24, 2026 at 21:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Data Modification via HTTP in Oracle Hyperion Financial Reporting

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Low Privilege Data Modification through HTTP in Oracle Hyperion Financial Reporting
Weaknesses CWE-284

Wed, 19 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Low Privilege Data Modification through HTTP in Oracle Hyperion Financial Reporting
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 2.6 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Financial Reporting
CPEs cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Reporting
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Oracle Hyperion Financial Reporting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:23:43.484Z

Reserved: 2026-08-04T22:06:34.596Z

Link: CVE-2026-70776

cve-icon Vulnrichment

Updated: 2026-08-24T14:08:07.337Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:30.613

Modified: 2026-08-24T15:43:44.880

Link: CVE-2026-70776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:00:04Z

Weaknesses