Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This local security flaw in Oracle Hyperion Financial Management version 11.2.25.0.000, documented as CWE-200, allows an attacker who can log onto the infrastructure where the application runs to read a subset of data that is normally protected. The defect resides in the Security component and represents a confidentiality breach. The CVSS 3.1 vector indicates a local attack (AV:L) with low complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N), and unchanged scope (S:U); it produces a 4.0 Base Score that impacts confidentiality only.

Affected Systems

The affected product is Oracle Hyperion Financial Management, version 11.2.25.0.000, which is part of the Oracle Hyperion suite of financial management tools. No other versions or components are listed as vulnerable.

Risk and Exploitability

Because the attacker must already have local access to the application host, the vulnerability cannot be exploited remotely. The attack requires low effort, no privileges, and no user interaction, making it relatively easy for a local adversary to read protected data. With a CVSS score of 4.0 the severity is moderate, but the EPSS score of approximately 0.13% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating that no widespread exploitation has been documented at this time.

Generated by OpenCVE AI on August 21, 2026 at 04:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch released by Oracle for version 11.2.25.0.000 to eliminate the flaw
  • If a patch is not yet available, restrict local access to the Hyperion servers with network segmentation and enforce least‑privilege policies
  • Enable audit logging on the Hyperion data repository and monitor for anomalous read activity to detect potential exploitation

Generated by OpenCVE AI on August 21, 2026 at 04:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Read via Local Access to Oracle Hyperion Financial Management
Weaknesses CWE-200

Thu, 20 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access to Confidential Data in Oracle Hyperion Financial Management via Local Security Flaw
Weaknesses CWE-200

Wed, 19 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access to Confidential Data in Oracle Hyperion Financial Management via Local Security Flaw
Weaknesses CWE-200

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T02:25:44.847Z

Reserved: 2026-08-04T22:06:34.605Z

Link: CVE-2026-70916

cve-icon Vulnrichment

Updated: 2026-08-22T02:25:39.880Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:49.357

Modified: 2026-08-24T15:47:24.577

Link: CVE-2026-70916

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T04:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor