Impact
The Oracle Hyperion Financial Management 11.2.26.0.000 vulnerability is triggered by an unauthenticated attacker who can physically reach the communication segment on the host hardware. Exploitation bypasses authentication (CWE‑269) and grants full control of the application, leading to a compromise of confidentiality, integrity, and availability. The weakness permits taking over the entire application without any user interaction, and the identification of a scope change means that other connected Oracle products could also be affected if the same hardware is used to host them.
Affected Systems
Oracle Hyperion Financial Management version 11.2.26.0.000 is the only product and version explicitly listed as vulnerable; no other releases are indicated in the advisory.
Risk and Exploitability
The CVSS base score of 9.6 signals critical severity, while the EPSS score of less than 1% indicates that the current likelihood of exploitation is low. Nonetheless, physical access to the server’s network segment eliminates the need for network connectivity or privileged accounts, making a successful attack both plausible and devastating. The vulnerability is not present in the CISA KEV catalog.
OpenCVE Enrichment