Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the Security component of Oracle Hyperion Financial Management, allowing an attacker with low privileges and network access to send arbitrary SQL commands. This flaw enables the attacker to obtain full control over the application, including the ability to read or modify any data and to take over the system. As a result, confidentiality, integrity, and availability are all severely impacted, matching the CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.

Affected Systems

Affected are users running Oracle Hyperion Financial Management version 11.2.25.0.000. No other versions are known to be impacted, but users should verify their deployment against the security alert for changes.

Risk and Exploitability

With a CVSS 3.1 base score of 8.8 the vulnerability is considered high severity. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not yet listed in CISA KEV. The likely attack vector is network-based, requiring the attacker to send crafted SQL statements to the vulnerable component. The low attack complexity and low privileges required for exploitation mean that any host with network connectivity to the Hyperion instance could be used as a launch point, making the risk significant for exposed systems.

Generated by OpenCVE AI on August 24, 2026 at 21:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the latest security patch for Oracle Hyperion Financial Management from Oracle's August 2026 security alert (https://www.oracle.com/security-alerts/cspuaug2026.html).
  • Limit network access to the Hyperion server by restricting inbound traffic to trusted IP addresses or VPN connections only.
  • Enforce least‑privilege database access by ensuring the application connects with a database user that has no unnecessary schema privileges, and review permissions regularly.
  • Validate input to all SQL interfaces, applying parameterized queries or stored procedures where feasible, to eliminate the possibility of future injection vulnerabilities.

Generated by OpenCVE AI on August 24, 2026 at 21:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title SQL Injection Enables Low-Privilege Takeover of Oracle Hyperion Financial Management

Mon, 24 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title SQL Injection Enables Low-Privilege Takeover of Oracle Hyperion Financial Management
Weaknesses CWE-20
CWE-89

Fri, 21 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Low Privilege SQL Attack Allows Full Compromise of Oracle Hyperion Financial Management
Weaknesses CWE-284
CWE-89

Wed, 19 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Low Privilege SQL Attack Allows Full Compromise of Oracle Hyperion Financial Management
Weaknesses CWE-284
CWE-89

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:21:45.747Z

Reserved: 2026-08-04T22:06:34.599Z

Link: CVE-2026-70818

cve-icon Vulnrichment

Updated: 2026-08-24T15:12:43.418Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:36.620

Modified: 2026-08-24T18:39:45.490

Link: CVE-2026-70818

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:15:07Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')