Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows a low‑privileged attacker with network access to the Oracle Hyperion Financial Management web interface to read all exposed data and cause a partial denial of service. The impact includes confidentiality loss for critical data and availability degradation.

Affected Systems

Oracle Corporation’s Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. No other versions or products are listed as vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 7.1 indicates a high impact, with significant confidentiality and availability effects. The EPSS score is less than 1%. The vulnerability is not yet catalogued in CISA’s KEV list. Based on the description, it is inferred that the attacker requires low‑privileged network access to the Hyperion instance over HTTP, but the advisory does not explicitly state whether authentication is required or if any elevated privileges are necessary.

Generated by OpenCVE AI on August 21, 2026 at 03:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch for Oracle Hyperion Financial Management 11.2.25.0.000 or upgrade to a later, fixed release
  • Restrict external HTTP access to the Hyperion application by placing it behind a firewall or within a bastion host so only trusted network segments can reach it
  • Configure role‑based access control to ensure users have only the permissions necessary, and review any custom mappings for potential privilege escalation
  • Enforce proper access control checks within the Hyperion application to prevent unauthorized data retrieval
  • Monitor logs for anomalous authentication attempts or access patterns that may indicate exploitation attempts

Generated by OpenCVE AI on August 21, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Exploit Enables Unauthorized Data Access and Partial DOS in Oracle Hyperion Financial Management

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Exploit Enables Unauthorized Data Access and Partial DOS in Oracle Hyperion Financial Management
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:09.891Z

Reserved: 2026-08-04T22:06:34.606Z

Link: CVE-2026-70935

cve-icon Vulnrichment

Updated: 2026-08-19T12:10:13.607Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:51.550

Modified: 2026-08-24T18:11:03.287

Link: CVE-2026-70935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T03:30:09Z

Weaknesses