Impact
The vulnerability resides in the security component of the Oracle Hyperion Financial Management product. It permits an unauthenticated attacker who can reach the system over HTTP to bypass authentication and gain full control of the instance. This results in the compromised confidentiality, integrity, and availability of financial data and the Oracle Hyperion application. The weakness is rooted in improper authentication (CWE-287) and missing authentication enforcement (CWE-306). Based on the description, it is inferred that unauthorized access could allow attackers to alter financial reports, hide fraudulent entries, or disrupt business operations.
Affected Systems
Version 11.2.26.0.000 of Oracle Hyperion Financial Management from Oracle Corporation is known to be affected. The vulnerability is limited to that exact build; other releases are not reported as vulnerable. Any deployment of this build that is reachable over the network without proper access restrictions is at risk.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 demonstrates severe impact. EPSS < 1% indicates a very low, but still non‑zero, likelihood of exploitation. It is not listed in the CISA KEV catalog. The most likely attack vector is an unauthenticated HTTP request sent from a remote machine, exploiting the authentication failure. Attackers would require network connectivity to the Hyperion web service, but no additional privileges are needed to launch the attack.
OpenCVE Enrichment