Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw located in the Security component of Oracle Hyperion Financial Management. A low‑privileged attacker who can reach the system over HTTP can bypass authorization checks and read any data available to the application, including critical or all application data. The weaknesses are CWE-269 and CWE-284. The damage is limited to confidentiality, with no impact on integrity or availability reported.

Affected Systems

Oracle Hyperion Financial Management version 11.2.25.0.000. No other versions or product variants are listed as affected.

Risk and Exploitability

The CVSS 3.1 base score of 6.5 indicates a moderate to high risk. The attack can be carried out with only network access and low privileges, and no user interaction is required. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but the description notes it is easily exploitable and could have significant confidentiality impact if discovered by a low‑privileged adversary.

Generated by OpenCVE AI on August 24, 2026 at 20:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a version that the fix as detailed in Oracle's security advisory
  • Restrict external HTTP access to Hyperion Financial Management using firewall rules or VPN to reduce the attack surface
  • Enforce strict application-level access controls, disabling unused features and ensuring permissions follow least privilege principles

Generated by OpenCVE AI on August 24, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Hyperion Financial Management Allows Low‑Privileged Remote Data Access

Mon, 24 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Fri, 21 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Attack Enables Unauthorized Data Access in Oracle Hyperion Financial Management

Thu, 20 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Attack Enables Unauthorized Data Access in Oracle Hyperion Financial Management
Weaknesses CWE-284

Wed, 19 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Title Network-Accessible Vulnerability in Oracle Hyperion Financial Management Allows Unauthorized Data Access
Weaknesses CWE-284

Wed, 19 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Network-Accessible Vulnerability in Oracle Hyperion Financial Management Allows Unauthorized Data Access
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:18:33.245Z

Reserved: 2026-08-04T22:06:34.609Z

Link: CVE-2026-70969

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:55.537

Modified: 2026-08-24T18:25:33.327

Link: CVE-2026-70969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:30:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control