Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is in the server component of Oracle Hyperion Financial Reporting and allows an unauthenticated attacker to interact over HTTP. The sidestepping of authentication and requirement for a human interaction outside the attacker’s immediate control enable the attacker to traverse the system. When exploited, the attacker can read critical data, gain full visibility of all data accessible through the application, and carry out unauthorized updates, inserts, or deletions, thereby compromising confidentiality and integrity.

Affected Systems

Oracle Corporation’s Hyperion Financial Reporting, version 11.2.25.0.000. This is the only product version explicitly listed as affected.

Risk and Exploitability

The CVSS 3.1 base score of 5.9 denotes moderate severity with high attack complexity, no privilege escalation, and a user interaction requirement. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating it has not yet been exploited at scale. Nevertheless, once active, the attack offers an attacker substantial data‑gathering and data‑manipulation capabilities. The attack vector is network‑based via HTTP and can only be performed with the cooperation of a separate user.

Generated by OpenCVE AI on August 21, 2026 at 05:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or update to a non‑affected version
  • Restrict HTTP access to Hyperion by firewalling or moving the service behind a VPN or internal network
  • Enforce robust authentication and access controls, ensuring only authorized users can reach the application endpoints
  • Monitor application logs for anomalous data modification attempts

Generated by OpenCVE AI on August 21, 2026 at 05:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Access in Oracle Hyperion Financial Reporting
Weaknesses CWE-284

Wed, 19 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Allowing Unauthorized Data Access in Oracle Hyperion Financial Reporting
Weaknesses CWE-285
CWE-286

Wed, 19 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Allowing Unauthorized Data Access in Oracle Hyperion Financial Reporting
Weaknesses CWE-285
CWE-286

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Financial Reporting
CPEs cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Reporting
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Hyperion Financial Reporting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:23:18.801Z

Reserved: 2026-08-04T22:06:34.597Z

Link: CVE-2026-70789

cve-icon Vulnrichment

Updated: 2026-08-24T14:08:05.111Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:32.527

Modified: 2026-08-24T16:11:28.580

Link: CVE-2026-70789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T05:45:03Z

Weaknesses