Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local attacker who has obtained logon access to the infrastructure hosting Oracle Hyperion Financial Management can exploit a security flaw that bypasses authentication checks. The flaw requires the cooperation of a separate individual to complete the attack but, once executed, it allows the attacker to take full control of the application, compromising the confidentiality, integrity, and availability of financial data.

Affected Systems

Oracle Hyperion Financial Management version 11.2.25.0.000, a product of Oracle Corporation.

Risk and Exploitability

The vulnerability has a CVSS v3.1 score of 7.0, indicating high severity. The EPSS score is below 1 percent and the flaw is not listed in the CISA KEV catalog. The attack vector is local (AV:L); the attacker needs to be logged on to the infrastructure and rely on a separate person to provide the required human interaction. The complexity of the exploit (AC:H, PR:N) means it is difficult to carry out, yet successful exploitation results in complete takeover of the application.

Generated by OpenCVE AI on August 22, 2026 at 06:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle security update for Oracle Hyperion Financial Management 11.2.25.0.000, as documented in Oracle's August 2026 security alert.
  • Restrict local access to the servers running Oracle Hyperion Financial Management, ensuring that only authorized personnel have login privileges and that privileged accounts are protected by strong, unique credentials.
  • If the patch is not yet available, disable or limit the vulnerable functionality through configuration changes to reduce the risk of exploitation while remediation is pending.

Generated by OpenCVE AI on August 22, 2026 at 06:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Authentication Bypass Allowing Application Takeover
Weaknesses CWE-287

Sat, 22 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Local Authentication Bypass Allowing Application Takeover
Weaknesses CWE-287

Thu, 20 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass with External Interaction Leads to Application Takeover
Weaknesses CWE-284

Wed, 19 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass with External Interaction Leads to Application Takeover
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T02:24:38.967Z

Reserved: 2026-08-04T22:06:34.605Z

Link: CVE-2026-70914

cve-icon Vulnrichment

Updated: 2026-08-22T02:24:33.667Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:49.223

Modified: 2026-08-24T15:47:41.827

Link: CVE-2026-70914

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T06:45:04Z

Weaknesses