Sceawere

Vulnerability Detail

CVE-2026-70730UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Profitability Deployment Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Profitability and Cost Management
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Profitability and Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Profitability and Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-18T21:17:25.610Z",
  "pubdate": "2026-08-18T21:17:25.610Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Deployment component of Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000. This security flaw allows unauthenticated remote attackers with network access via HTTP to compromise the affected system without requiring user interaction.\nSuccessful exploitation of this vulnerability has severe risk implications, leading to unauthorized creation, deletion, or modification access to critical data, as well as complete unauthorized access to all accessible data within Oracle Hyperion Profitability and Cost Management. The CVSS 3.1 Base Score is 9.1, reflecting high impacts on both confidentiality and integrity.\nThe vulnerability requires zero privileges and low attack complexity, making it a critical exposure for organizations utilizing the affected software version. Immediate remediation is necessary to prevent potential data breaches and unauthorized data tampering.",
  "technicalDetails": "The vulnerability resides in the Deployment component of Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000. It is exposed over the network via the HTTP protocol, allowing remote threat actors to interact directly with the vulnerable application endpoints without prior authentication.\nThe attack flow begins when an unauthenticated attacker sends specially crafted HTTP requests to the target Oracle Hyperion Profitability and Cost Management server. Due to insufficient input validation, authorization checks, or improper access control enforcement within the Deployment component, the application fails to restrict unauthorized command or data handling operations.\nBecause the vulnerability requires no privileges (PR:N) and no user interaction (UI:N) over a network attack vector (AV:N) with low attack complexity (AC:L), an adversary can automate the delivery of malicious payloads. Once processed by the vulnerable component, the payload bypasses security controls, granting the attacker the ability to interact with backend data structures.\nThe post-exploitation impact includes complete compromise of data confidentiality and integrity. The attacker gains unauthorized read access to sensitive corporate financial and analytical data stored within the application, as well as unauthorized write, update, and delete capabilities. This allows malicious actors to exfiltrate critical information or sabotage system data integrity, while availability (A:N) remains unaffected by the core mechanics of this specific vector."
}
CVE-2026-70730: Oracle Hyperion Profitability Deployment Vulnerability (CRITICAL Severity, CVSS: 9.1) - Sceawere