Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the security component of Oracle Hyperion Financial Management, permitting a high‑privileged attacker with network SQL access to circumvent authentication and alter the system’s financial records. Such misuse can cause unauthorized creation, deletion, or modification of sensitive data, thereby undermining both confidentiality and integrity. The impact is that attackers can manipulate or expose all data the application protects.

Affected Systems

Oracle Hyperion Financial Management version 11.2.25.0.000 is affected. No other versions are mentioned as vulnerable. Attackers must target this specific release running the vulnerable component.

Risk and Exploitability

The CVSS 3.1 base score of 6.5 indicates moderate severity with high confidentiality and integrity impact. The EPSS score being below 1% signals a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the exploit requires a high‑privileged attacker who already has database connectivity; once that privilege is attained, the vulnerability is easily exploitable without additional user interaction. The threat vector is inferred to be network‑based SQL access, as the description indicates a need for network access via SQL.

Generated by OpenCVE AI on August 20, 2026 at 19:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's official patch or upgrade to a version where the vulnerability has been addressed.
  • Limit privileged database access by granting only the minimal privileges required for each account, ensuring that high‑privileged accounts are tightly controlled.
  • Enforce strict role‑based access control within the Hyperion application, configuring users so that only authorized roles can create, delete, or modify critical data.
  • Implement monitoring of SQL activity to detect anomalous data‑modification patterns, enabling quick response to potential abuse.

Generated by OpenCVE AI on August 20, 2026 at 19:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title High‑privilege SQL Exploit Allows Unauthorized Data Modification in Oracle Hyperion Financial Management

Thu, 20 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title High‑privilege SQL Exploit Allows Unauthorized Data Modification in Oracle Hyperion Financial Management

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title SQL Injection in Oracle Hyperion Financial Management 11.2.25.0.000 Allowing Unauthorized Data Modification
Weaknesses CWE-89

Wed, 19 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in Oracle Hyperion Financial Management 11.2.25.0.000 Allowing Unauthorized Data Modification
Weaknesses CWE-89

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:02:14.989Z

Reserved: 2026-08-04T22:06:34.616Z

Link: CVE-2026-71091

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:09.337

Modified: 2026-08-20T15:22:49.293

Link: CVE-2026-71091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T19:15:04Z

Weaknesses