Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Hyperion Financial Reporting version 11.2.25.0.000 contains an unauthorized access flaw that enables an attacker with physical network access to the server’s communication segment to create, delete, or modify critical data. The flaw is a weakness in access control that can be exploited without authentication, and availability is unaffected. The CVSS v3.1 score of 6.8 reflects significant confidentiality and integrity loss while availability is unaffected.

Affected Systems

The vulnerability affects Oracle Hyperion Financial Reporting, a product of Oracle Corporation, in its 11.2.25.0.000 release. No other versions or components are known to be impacted.

Risk and Exploitability

The vector is local physical access (AV:A) and the attack is difficult to execute, yet possible if an adversary controls the network segment of the hardware running Oracle Hyperion. With a CVSS base score of 6.8 and an EPSS score of < 1%, the likelihood of exploitation is very low; it is not listed in the CISA KEV catalog. The breach would allow an attacker to alter or delete financial data, undermining the integrity of the reporting system.

Generated by OpenCVE AI on August 21, 2026 at 09:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Hyperion Financial Reporting 11.2.25.0.000 as soon as it is released by Oracle.
  • Restrict physical network access to the Oracle Hyperion server, limiting connectivity to trusted personnel and secure VLANs.
  • Implement and regularly audit fine‑grained data access controls within Oracle Hyperion to detect and prevent unauthorized modifications.

Generated by OpenCVE AI on August 21, 2026 at 09:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Physical Network Access Allows Unauthorized Data Modification in Oracle Hyperion Financial Reporting
Weaknesses CWE-284

Fri, 21 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Physical Access Data Modification Vulnerability in Oracle Hyperion Financial Reporting
Weaknesses CWE-284

Wed, 19 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Physical Access Data Modification Vulnerability in Oracle Hyperion Financial Reporting
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Financial Reporting
CPEs cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Reporting
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Financial Reporting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:22:44.100Z

Reserved: 2026-08-04T22:06:34.596Z

Link: CVE-2026-70780

cve-icon Vulnrichment

Updated: 2026-08-24T15:12:53.825Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:31.220

Modified: 2026-08-25T14:14:25.513

Link: CVE-2026-70780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T09:30:09Z

Weaknesses