Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local attacker who possesses high‑privileged credentials on the host where Oracle Hyperion Financial Management runs can exploit a flaw in the product’s security component. The vulnerability is difficult to exploit, but when successful it provides full control over the application, allowing the attacker to read, modify, or delete data and potentially disrupt service availability. The impact covers confidentiality, integrity and availability of the Hyperion application data. The weakness is consistent with a privilege‑escalation flaw classified as CWE-284.

Affected Systems

The flaw affects Oracle Corporation’s Hyperion Financial Management, version 11.2.25.0.000, in the security component of the product.

Risk and Exploitability

The base CVSS score of 6.4 indicates a moderate severity, with the attack vector limited to local access (AV:L) and requiring high privileged user rights (PR:H). Because the attacker must already have a logon on the infrastructure that hosts Hyperion, the exploit is not remotely achievable from outside the network. EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, which suggests that widespread exploitation has not yet been observed. However, the potential for full application takeover warrants proactive mitigation.

Generated by OpenCVE AI on August 20, 2026 at 17:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade Oracle Hyperion Financial Management to a version that includes the fix for CVE‑2026‑71119.
  • Restrict local access to the host running Hyperion so that only trusted, least‑privileged accounts have logon rights.
  • Implement continuous monitoring for privileged account activity on the Hyperion host to detect any unauthorized changes.

Generated by OpenCVE AI on August 20, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Hyperion Financial Management Allows Application Takeover

Thu, 20 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Hyperion Financial Management Allows Application Takeover

Thu, 20 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Hyperion Financial Management via Security Component
Weaknesses CWE-269

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Hyperion Financial Management via Security Component
Weaknesses CWE-269

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:00:28.908Z

Reserved: 2026-08-04T22:06:34.618Z

Link: CVE-2026-71119

cve-icon Vulnrichment

Updated: 2026-08-19T15:02:23.731Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:12.593

Modified: 2026-08-24T18:11:11.330

Link: CVE-2026-71119

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T18:00:04Z

Weaknesses