Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Hyperion Financial Reporting allows a low‑privileged attacker with network access via HTTP to fully compromise the application, resulting in the attacker gaining complete control and affecting confidentiality, integrity, and availability of financial data.

Affected Systems

The vulnerability affects Oracle Hyperion Financial Reporting version 11.2.25.0.000.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and although EPSS is low at less than 1%, the vulnerability can still be exploited over a public HTTP interface by any low‑privileged attacker with network access. The issue is not listed in CISA KEV, but remote attackers only require connectivity and minimal permissions to achieve full compromise of the application, affecting confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 21, 2026 at 08:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest patch for Oracle Hyperion Financial Reporting 11.2.25.0.000 or higher.
  • Restrict HTTP access to the Hyperion instance by configuring firewalls or VPNs to allow only trusted IP ranges or user authentication.
  • Enable detailed logging of authentication and application access, and monitor for anomalous activity.

Generated by OpenCVE AI on August 21, 2026 at 08:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Full Compromise of Oracle Hyperion Financial Reporting 11.2.25.0.000
Weaknesses CWE-284

Fri, 21 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Full Control Acquisition for Oracle Hyperion Financial Reporting via Low‑Privilege HTTP Attack
Weaknesses CWE-287

Wed, 19 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Full Control Acquisition for Oracle Hyperion Financial Reporting via Low‑Privilege HTTP Attack
Weaknesses CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Reporting
CPEs cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Reporting
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Reporting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:22:37.436Z

Reserved: 2026-08-04T22:06:34.597Z

Link: CVE-2026-70787

cve-icon Vulnrichment

Updated: 2026-08-24T15:12:52.655Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:32.247

Modified: 2026-08-25T14:14:20.370

Link: CVE-2026-70787

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T08:30:04Z

Weaknesses