Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is located in the Security component of Oracle Hyperion Financial Management. This flaw involves improper authorization and privilege management, corresponding to CWE-284. A local, high‑privilege attacker who has logged on to the infrastructure hosting the application can exploit this weakness to completely compromise the application, leading to full confidentiality, integrity, and availability loss.

Affected Systems

Oracle Corporation's Oracle Hyperion Financial Management, version 11.2.25.0.000. The vulnerability is present only in this exact build of the product and does not affect other versions or unrelated Oracle software.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates a high impact, and the vector (AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H) shows that the exploit requires local access and high privileges but does not require user interaction. Successful exploitation results in a scope change, allowing the attacker to takeover the application and potentially affect other connected products. The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, so the immediate threat level remains governed primarily by the high CVSS score and the local privilege requirement.

Generated by OpenCVE AI on August 20, 2026 at 17:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • If an official Oracle patch is released for this vulnerability, apply it promptly.
  • If a patch is not yet available, segregate the Hyperion infrastructure from other systems, enforce strict hostname‑based access controls, and ensure the application runs under the least privileged account necessary.
  • Implement continuous monitoring of Hyperion logs for anomalous activity and restrict file‑system permissions to prevent unauthorized changes to application binaries.

Generated by OpenCVE AI on August 20, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Application Takeover in Oracle Hyperion Financial Management 11.2.25.0.000

Thu, 20 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Application Takeover in Oracle Hyperion Financial Management 11.2.25.0.000

Wed, 19 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Vulnerability in Oracle Hyperion Financial Management Allows High‑Privilege User to Take Over the Application
Weaknesses CWE-285

Wed, 19 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Vulnerability in Oracle Hyperion Financial Management Allows High‑Privilege User to Take Over the Application
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:00:40.002Z

Reserved: 2026-08-04T22:06:34.618Z

Link: CVE-2026-71117

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:12.350

Modified: 2026-08-24T18:11:07.390

Link: CVE-2026-71117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T18:00:04Z

Weaknesses