Impact
The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. An attacker with low‑priv flaw, resulting in full compromise of the application. Successful exploitation would grant the attacker complete control, allowing arbitrary modification of financial data and disruption of services. The weakness leads to loss of confidentiality, integrity and availability, as reflected in the CVSS vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.
Affected Systems
The vulnerability affects Oracle Hyperion Financial Management version 11.2.26.0.000. No other vendors or product variants were identified in the CNA data. The flaw is limited to this specific build; users of other releases are unaffected unless an identical flaw has propagated further.
Risk and Exploitability
The CVSS base score of 7.0 indicates high severity, but the EPSS score of less than 1% suggests that exploitation is currently unlikely to be seen in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local logon rights; the vector is limited to individuals already authenticated to the infrastructure. Once the flaw is triggered, the attacker can achieve application takeover with no user interaction, making it a potent threat for environments where local privileges are loosely enforced.
OpenCVE Enrichment