Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000, allowing an unauthenticated attacker with network access via HTTP to compromise the application. A successful exploit can lead to full takeover of the system, giving the attacker the ability to read, modify, or delete any financial data and potentially execute arbitrary code on the host. The weakness is a form of improper input validation that permits remote code execution.

Affected Systems

The affected product is Oracle Hyperion Financial Management 11.2.25.0.000. No other versions or products were specifically identified as impacted. The vulnerability lies within the Security component of this version, so any deployment of 11.2.25.0.000 that is not patched remains at risk.

Risk and Exploitability

The CVSS 3.1 Base Score of 9.8 marks this vulnerability as critical. While the EPSS score is not available, the lack of a KEV listing does not reduce the high potential impact. Because the attacker needs only network access over HTTP and no authentication or user interaction, exploitation is highly feasible for exposed deployments. Administrators should treat this as an urgent threat and prioritize remediation.

Generated by OpenCVE AI on August 19, 2026 at 02:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-supplied patch for Oracle Hyperion Financial Management 11.2.25.0.000 as released by Oracle.
  • Restrict HTTP access to the Hyperion instance by configuring firewall rules or VPN to allow only trusted IP addresses until the patch can be applied.
  • Disable or block the vulnerable security component endpoints within the application so that the exposed functionality is no longer reachable until the fix is deployed.

Generated by OpenCVE AI on August 19, 2026 at 02:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Hyperion Financial Management
Weaknesses CWE-20

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:01:58.706Z

Reserved: 2026-08-04T22:06:34.599Z

Link: CVE-2026-70817

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:36.490

Modified: 2026-08-18T21:17:36.490

Link: CVE-2026-70817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T02:30:03Z

Weaknesses
  • CWE-20

    Improper Input Validation