Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Hyperion Financial Management contains a flaw in its security component that allows unauthenticated attackers with network access over HTTP to obtain unauthorized access to critical data or full database contents and to trigger a partial denial of service. The CVSS 3.1 score of 8.2 highlights a high impact on confidentiality and availability, with no impact on integrity as indicated by the vector.

Affected Systems

The vulnerability affects Oracle Hyperion Financial Management version 11.2.25.0.000. No other versions are mentioned as impacted in the available data.

Risk and Exploitability

The attack vector is inferred to be a network-based HTTP request that can be sent without authentication. The EPSS score of <1% indicates a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA KEV. The high CVSS score signals a serious risk if the application is exposed to the internet, while the lack of an official exploitation reference suggests attackers could still craft exploits using the known flaw but external proof of exploitation has not yet been reported.

Generated by OpenCVE AI on August 21, 2026 at 03:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Hyperion Financial Management security patch or upgrade to a version that includes the fix as detailed in Oracle’s August 2026 security advisory.
  • Restrict HTTP access to the Hyperion application by enforcing firewall or VPN rules, limiting exposure to trusted networks only.
  • Verify and reinforce authentication controls on all Hyperion endpoints, ensuring that no privileged data is exposed to unauthenticated users, in line with principle of least privilege.

Generated by OpenCVE AI on August 21, 2026 at 03:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Unattended HTTP Access Enables Data Breach and Partial Denial of Service in Oracle Hyperion Financial Management

Thu, 20 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Access via HTTP in Oracle Hyperion Financial Management
Weaknesses CWE-285

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Access via HTTP in Oracle Hyperion Financial Management
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:09.741Z

Reserved: 2026-08-04T22:06:34.608Z

Link: CVE-2026-70952

cve-icon Vulnrichment

Updated: 2026-08-19T12:10:05.735Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:53.493

Modified: 2026-08-24T18:11:05.663

Link: CVE-2026-70952

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T03:15:03Z

Weaknesses