Impact
The vulnerability is located in the Security component of Oracle Hyperion Financial Management. An attacker who already has local logon credentials of low privilege can exploit this flaw to compromise the entire Hyperion instance. The flaw allows bypassing built‑in access controls and grants full confidentiality, integrity, and availability damage. It is represented by a local attack vector and can lead to a complete takeover of the application.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is the identified affected release. The CVSS vector notes a scope change, indicating that a corruption of Hyperion could potentially impact other Oracle products or modules that share the same infrastructure.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 marks this as a high‑severity vulnerability, though the EPSS score is reported as < 1 %, suggesting a low likelihood of exploitation in the short term. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local or low‑privileged access to the server running Hyperion, and the exploit does not require network interaction. The S:C vector indicates that while the flaw originates in Hyperion, compromise could hypothetically affect other products that share the same environment.
OpenCVE Enrichment