Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Hyperion Financial Management users can exploit an easily exploitable flaw in the Security component that allows a low‑privileged attacker with network access over HTTP to fully compromise the application. Successful exploitation results in a complete takeover, compromising confidentiality, integrity, and availability of the system. The CVSS 3.1 Base Score of 8.8 reflects the severe impact on all three fundamental security categories.

Affected Systems

Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. The vulnerability is present in the Security component of this software and applies to all installations that have not applied a patch or upgrade for this release.

Risk and Exploitability

The high CVSS score indicates a significant risk for organizations using the affected product. The vulnerability is exploitable over the network via HTTP without user interaction, and only low privileges are required to launch the attack. The EPSS score is < 1%, indicating a very low probability of exploitation, and the absence in the CISA KEV catalog does not diminish the potential for active exploitation. The attack vector is likely remote web traffic, and an attacker could achieve full system compromise once the flaw is used.

Generated by OpenCVE AI on August 24, 2026 at 20:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Oracle Hyperion Financial Management 11.2.25.0.000 that addresses the Security component flaw.
  • Restrict network access to the HTTP interface of the impacted Hyperion instance to trusted hosts or internal networks only.
  • Enable detailed auditing and monitor logs for anomalous authentication or administrative activity to detect potential exploitation attempts.

Generated by OpenCVE AI on August 24, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Leading to Total System Takeover in Oracle Hyperion Financial Management

Mon, 24 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Sat, 22 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title HTTP Low‑Privilege Exploit for System Takeover in Oracle Hyperion

Sat, 22 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title HTTP Low‑Privilege Exploit for System Takeover in Oracle Hyperion
Weaknesses CWE-284

Sat, 22 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Wed, 19 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Remote Exploitation Allows Takeover of Oracle Hyperion Financial Management

Wed, 19 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Remote Exploitation Allows Takeover of Oracle Hyperion Financial Management
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T03:13:54.982Z

Reserved: 2026-08-04T22:06:34.607Z

Link: CVE-2026-70940

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:52.113

Modified: 2026-08-24T18:37:57.613

Link: CVE-2026-70940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:30:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-306

    Missing Authentication for Critical Function