Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the security component of Oracle Hyperion Financial Management, affecting version 11.2.25.0.000. A low‑privileged attacker with network access over HTTP can exploit this flaw, potentially gaining full control of the application and compromising confidentiality, integrity and availability of the financial data.

Affected Systems

The affected product is Oracle Hyperion Financial Management 11.2.25.0.000 from Oracle Corporation.

Risk and Exploitability

The CVSS base score of 7.5 indicates moderate‑to‑high severity, with a network attack vector, high authentication difficulty, low privilege and no user interaction. The EPSS score of < 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only network access to the Hyperion HTTP interface and does not require privileged credentials, making this a realistic risk for exposed deployments.

Generated by OpenCVE AI on August 24, 2026 at 20:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Oracle security patch for Hyperion Financial Management 11.2.25.0.000 from the Oracle Support portal.
  • Restrict HTTP access to the Hyperion application to a secure network segment or VPN, limiting exposure to low‑privileged attackers.
  • Monitor web server logs for anomalous requests to Hyperion endpoints and review authentication and authorization configuration to ensure no unknown privileged users are present.

Generated by OpenCVE AI on August 24, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Financial Management Unauthorized Access Leading to Full Compromise

Mon, 24 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Sun, 23 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 22 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Financial Management Unauthorized Access Leading to Full Compromise

Sat, 22 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Full Compromise of Oracle Hyperion Financial Management
Weaknesses CWE-264
CWE-287

Sat, 22 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 21 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Full Compromise of Oracle Hyperion Financial Management
Weaknesses CWE-264
CWE-287

Fri, 21 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP Exploit Grants Full Control of Oracle Hyperion Financial Management
Weaknesses CWE-284

Thu, 20 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP Exploit Grants Full Control of Oracle Hyperion Financial Management
Weaknesses CWE-284

Wed, 19 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP Exploit Enables Full Application Takeover of Oracle Hyperion Financial Management
Weaknesses CWE-284

Wed, 19 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP Exploit Enables Full Application Takeover of Oracle Hyperion Financial Management
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T03:09:28.465Z

Reserved: 2026-08-04T22:06:34.607Z

Link: CVE-2026-70937

cve-icon Vulnrichment

Updated: 2026-08-22T03:09:21.626Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:51.777

Modified: 2026-08-24T18:38:08.267

Link: CVE-2026-70937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control