Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H).
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Hyperion Financial Management product contains an easily exploitable flaw in its Security component. This flaw is an instance of CWE‑269 and CWE‑284. A high privileged attacker who can reach the application over HTTP may gain unauthorized access to critical data or achieve full data set access, and can also force the application to hang or crash, creating a denial‑of‑service condition. The flaw carries confidentiality and availability impacts, reflected in a CVSS 3.1 Base Score of 6.5.

Affected Systems

Only Oracle Hyperion Financial Management version 11.2.25.0.000 is affected; no other versions were mentioned in the advisory.

Risk and Exploitability

The vector allows network access with HTTP, and the required privilege level is high. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, but the potential for compromising all exposed data or causing a denial‑of‑service remains significant. The CVSS score of 6.5 indicates a moderate severity that warrants timely remediation.

Generated by OpenCVE AI on August 24, 2026 at 21:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s official patch for CVE-2026-70849 as soon as it becomes available.
  • Limit HTTP access to trusted hosts or internal network segments to reduce exposure to potential attackers.
  • Monitor Hyperion logs and network traffic for anomalous authentication attempts or application crashes and investigate promptly.

Generated by OpenCVE AI on August 24, 2026 at 21:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Financial Management Privileged HTTP Attack Vulnerability

Mon, 24 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Financial Management Privileged HTTP Attack Vulnerability
Weaknesses CWE-284

Wed, 19 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title High Privilege Action via HTTP Allows Unauthorized Access and Denial of Service in Oracle Hyperion Financial Management
Weaknesses CWE-284
CWE-400

Wed, 19 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title High Privilege Action via HTTP Allows Unauthorized Access and Denial of Service in Oracle Hyperion Financial Management
Weaknesses CWE-284
CWE-400

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:21:47.261Z

Reserved: 2026-08-04T22:06:34.601Z

Link: CVE-2026-70849

cve-icon Vulnrichment

Updated: 2026-08-24T14:07:51.075Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:40.830

Modified: 2026-08-24T18:39:47.700

Link: CVE-2026-70849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:00:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control