Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Hyperion Financial Management is susceptible to a remotely exploitable flaw in its security component that allows a low‑privileged attacker with network visibility through HTTP to take full control of the application. The vulnerability can result in complete compromise of the system’s confidentiality, integrity, and availability.

Affected Systems

The affected product is Oracle Hyperion Financial Management version 11.2.25.0.000, released by Oracle Corporation. No other versions are listed as vulnerable in the current advisory.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 indicates a high‑impact flaw. With an EPSS score of less than 1 % and the vulnerability not being listed in the CISA KEV catalog, proof‑of‑concept exploitation is currently low but possible. Based on the CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), a remote attacker can send specially crafted HTTP requests without user interaction to trigger the flaw, leading to a takeover of the Hyperion service and associated data.

Generated by OpenCVE AI on August 24, 2026 at 21:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a non‑affected version as announced in the official security advisory
  • Restrict HTTP access to the Hyperion portal to trusted IP ranges or enforce VPN usage for remote connections
  • Enable multi‑factor authentication for privileged Hyperion accounts and monitor access logs for anomalous activity

Generated by OpenCVE AI on August 24, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP in Oracle Hyperion Financial Management 11.2.25.0.000

Mon, 24 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Fri, 21 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP in Oracle Hyperion Financial Management 11.2.25.0.000

Fri, 21 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Remote Vulnerability Allows Low-Privilege HTTP Attacker to Compromise Oracle Hyperion Financial Management
Weaknesses CWE-287

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Remote Vulnerability Allows Low-Privilege HTTP Attacker to Compromise Oracle Hyperion Financial Management
Weaknesses CWE-284
CWE-287

Thu, 20 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Remote System Compromise via HTTP Attack on Oracle Hyperion Financial Management 11.2.25.0.000
Weaknesses CWE-284
CWE-287

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote System Compromise via HTTP Attack on Oracle Hyperion Financial Management 11.2.25.0.000
Weaknesses CWE-284
CWE-287

Wed, 19 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Compromise of Oracle Hyperion Financial Management via HTTP
Weaknesses CWE-284
CWE-287

Wed, 19 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Compromise of Oracle Hyperion Financial Management via HTTP
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.25.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:59:05.330Z

Reserved: 2026-08-04T22:06:34.620Z

Link: CVE-2026-71150

cve-icon Vulnrichment

Updated: 2026-08-20T17:51:39.860Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:16.057

Modified: 2026-08-24T18:38:12.007

Link: CVE-2026-71150

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:15:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control