Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Hyperion Financial Management product (version 11.2.25.0.000) contains a security flaw that allows an unauthenticated attacker with network access over HTTP to compromise the application. Successful exploitation requires human interaction from a user other than the attacker and results in the ability to update, insert, or delete data as well as read restricted data. This flaw is caused by improper authorization (CWE‑269) and cross‑site request forgery (CWE‑352) mechanisms within the security component, allowing the attacker to bypass normal access controls. The flaw produces confidentiality and integrity impacts reflected in the CVSS 3.1 score of 5.4.

Affected Systems

Oracle Corporation’s Hyperion Financial Management, specifically the 11.2.25.0.000 release, is affected by this vulnerability.

Risk and Exploitability

Because the EPSS score indicates an exploitation probability of less than 1 % and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread recent exploitation is uncertain, yet the impact remains significant for organizations that rely on Hyperion for financial data integrity. The recommended response is therefore to mitigate through patching or hardening network access to the affected component.

Generated by OpenCVE AI on August 24, 2026 at 23:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Hyperion Financial Management to a version that is not affected by this vulnerability
  • Restrict HTTP access to the Hyperion application by implementing firewall rules or VPN segmentation
  • Enforce strong authentication and limit user privileges to prevent unauthorized data modification

Generated by OpenCVE AI on August 24, 2026 at 23:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Attack Allows Unauthorized Data Modification and Read in Oracle Hyperion Financial Management

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Hyperion Financial Management
Weaknesses CWE-287

Mon, 24 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Fri, 21 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Hyperion Financial Management
Weaknesses CWE-287

Thu, 20 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Enables Unauthorized Data Modification in Hyperion Financial Management
Weaknesses CWE-284

Wed, 19 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Enables Unauthorized Data Modification in Hyperion Financial Management
Weaknesses CWE-284

Wed, 19 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Hyperion Financial Management
Weaknesses CWE-284

Wed, 19 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Hyperion Financial Management
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T18:41:19.199Z

Reserved: 2026-08-04T22:06:34.618Z

Link: CVE-2026-71123

cve-icon Vulnrichment

Updated: 2026-08-24T18:41:12.119Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:13.060

Modified: 2026-08-24T19:16:48.610

Link: CVE-2026-71123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-352

    Cross-Site Request Forgery (CSRF)