Impact
Oracle Hyperion Financial Management, version 11.2.26.0.000, contains a security flaw that permits a low‑privileged attacker who can reach the service over HTTP to fully compromise the application. The vulnerability allows the attacker to achieve a takeover, leading to confidentiality, integrity, and availability impacts as indicated by the CVSS score. The weakness is a permissive authorization flaw (CWE‑269).
Affected Systems
Only Oracle Hyperion Financial Management version 11.2.26.0.000 is confirmed to be affected; no other releases have been reported to contain the defect.
Risk and Exploitability
The vulnerability can be triggered via HTTP by any host that can reach the Hyperion service, requiring only low‑privileged network access and no user interaction. The CVSS vector indicates a network attack (AV:N), high attack complexity (AC:H), and no user interface required (UI:N). With an EPSS score of less than 1% and the vulnerability not listed in the CISA KEV catalog, broad exploitation appears unlikely at present. However, the high CVSS score of 7.5 and the potential for complete application takeover mandate timely remediation.
OpenCVE Enrichment