Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the security component of Oracle Hyperion Financial Management allows an attacker to send HTTP requests without any authentication, granting access to sensitive financial data. The vulnerability can lead to unauthorized read of critical information or, in worst cases, complete exposure of all data stored in the application, while leaving system integrity and availability untouched. The weaknesses are classified as CWE-269 and CWE-284, reflecting improper access control and improper authorization controls respectively. The CVSS 3.1 base score of 7.5 highlights a moderate to high severity, driven by a network attack vector, low complexity, and no required user interaction.

Affected Systems

Oracle Hyperion Financial Management version 11.2.25.0.000 is vulnerable. The product operates behind standard HTTP interfaces and is susceptible to unauthenticated requests that can bypass authorization checks.

Risk and Exploitability

With a CVSS score of 7.5, this vulnerability poses a relatively high risk to confidentiality through an easily exploitable remote HTTP interface. The EPSS score indicates an exploitation probability of less than 1%, and the flaw is not listed in the CISA KEV catalog, but its high score and straightforward network path mean that attackers can trigger it from anywhere on the network without prior access or credentials. The attack requires only standard HTTP traffic, making containment a priority for affected deployments.

Generated by OpenCVE AI on August 24, 2026 at 22:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch or upgrade to a non‑affected version as outlined in the Oracle security advisory.
  • If a patch cannot be applied immediately, isolate Oracle Hyperion from public or untrusted networks; enforce firewall or VPN restrictions so that only authenticated connections can reach the HTTP interfaces.
  • Monitor web and application logs for anomalous or unauthenticated HTTP requests and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 24, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Leading to Unauthorized Data Exposure in Oracle Hyperion Financial Management

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Exposure in Oracle Hyperion Financial Management
Weaknesses CWE-285

Mon, 24 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Exposure in Oracle Hyperion Financial Management
Weaknesses CWE-285

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Remote Unauthorized Data Access via HTTP in Oracle Hyperion Financial Management
Weaknesses CWE-285

Wed, 19 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Remote Unauthorized Data Access via HTTP in Oracle Hyperion Financial Management
Weaknesses CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:22:21.367Z

Reserved: 2026-08-04T22:06:34.600Z

Link: CVE-2026-70832

cve-icon Vulnrichment

Updated: 2026-08-24T13:30:18.664Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:38.507

Modified: 2026-08-24T18:40:17.037

Link: CVE-2026-70832

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:00:06Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control