Impact
A flaw in the security component of Oracle Hyperion Financial Management 11.2.26.0.000 involves improper privilege management (CWE-269). An attacker who can reach the HTTP interface with only low-level credentials can authenticate and then perform unauthorized actions, thereby taking over the application and compromising confidentiality, integrity, and availability.
Affected Systems
The only affected product is Oracle Hyperion Financial Management version 11.2.26.0.000, as specified by the CNA and the only affected release listed in the description.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 classifies the issue as high severity. The EPSS score of less than 1% and the fact that the vulnerability is not listed in the CISA KEV catalog mean no known active exploits exist. Nevertheless, because exploitation requires only network access via HTTP and low-level credentials, the potential for a successful compromise remains significant for systems that expose the vulnerable service.
OpenCVE Enrichment