Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. A low‑privileged local account on the host where the application runs can exploit this flaw to create, delete, or modify critical financial data, or to obtain full read access to all Hyperion‑managed data, thereby compromising confidentiality and integrity.

Affected Systems

Affected systems include Oracle Hyperion Financial Management 11.2.25.0.000 deployed by Oracle Corporation. Because the flaw touches a core security mechanism, other Oracle products that share the same infrastructure or database can also be impacted if the exploitation scope expands.

Risk and Exploitability

The CVSS 3.1 Base Score of 8.4 indicates high severity with local availability, low access complexity, low privileges, and no user interaction. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog. The description infers that an attacker must already have logged on to the host running Hyperion; once local foothold is achieved, the impact extends to the entire Hyperion instance and potentially to other Oracle products on the same system.

Generated by OpenCVE AI on August 24, 2026 at 21:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle‑published security patch for Hyperion Financial Management 11.2.25.0.000 as documented in the Oracle security advisory.
  • Restrict local accounts on the Hyperion host to only those required by the service; disable unused local logons.
  • Segment the Hyperion environment from broader network traffic and enforce strict network segmentation to limit access.
  • Enable comprehensive audit logging of all data‑modification operations and review logs for anomalous activity.

Generated by OpenCVE AI on August 24, 2026 at 21:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Local Exploit Compromises Oracle Hyperion Financial Management Data

Mon, 24 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Exploit Enables Unauthorized Data Modification in Oracle Hyperion Financial Management
Weaknesses CWE-285

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Exploit Enables Unauthorized Data Modification in Oracle Hyperion Financial Management
Weaknesses CWE-269
CWE-285

Fri, 21 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Exploitation in Oracle Hyperion Financial Management Leading to Unauthorized Data Modification
Weaknesses CWE-284
CWE-732

Wed, 19 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Exploitation in Oracle Hyperion Financial Management Leading to Unauthorized Data Modification
Weaknesses CWE-284
CWE-732

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T03:56:36.932Z

Reserved: 2026-08-04T22:06:34.600Z

Link: CVE-2026-70840

cve-icon Vulnrichment

Updated: 2026-08-24T15:25:35.194Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:39.597

Modified: 2026-08-25T04:18:17.863

Link: CVE-2026-70840

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:00:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control