Sceawere

Vulnerability Detail

CVE-2026-70735UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Profitability Deployment Takeover

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Profitability and Cost Management
Attack Type
Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Profitability and Cost Management.
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Profitability and Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-18T21:17:26.213Z",
  "pubdate": "2026-08-18T21:17:26.213Z",
  "executiveSummary": "An easily exploitable security vulnerability affects the Deployment component of Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000. This vulnerability permits a network-adjacent or remote attacker possessing high privileges to compromise the target application entirely.\nSuccessful exploitation of this flaw results in the complete takeover of Oracle Hyperion Profitability and Cost Management, inflicting severe impacts across all three pillars of information security: confidentiality, integrity, and availability. The Common Vulnerability Scoring System (CVSS) version 3.1 assigns this issue a base score of 7.2, reflecting the high severity associated with complete administrative control despite the requirement for elevated privileges.\nThe attack vector relies on network access via the HTTP protocol, enabling threat actors with administrative credentials to leverage the deployment functionality maliciously. Risk implications include unauthorized disclosure of sensitive financial and operational data, malicious modification of enterprise profitability models, and complete disruption of core business services. Defensive strategies must focus on strict privilege management, network segmentation, and adherence to Oracle's official security advisory updates.",
  "technicalDetails": "The vulnerability resides within the Deployment component of Oracle Hyperion Profitability and Cost Management, specifically impacting version 11.2.25.0.000. The underlying root cause involves insufficient validation and authorization checks within administrative deployment routines exposed via HTTP endpoints.\nTo execute an attack, the adversary must first acquire high-level privileges within the application context. While the requirement for high privileges mitigates unauthenticated mass exploitation, it remains a critical risk in scenarios involving compromised administrative credentials, insider threats, or chained vulnerability exploits.\nThe attack flow proceeds as follows: The authenticated attacker leverages network access over the HTTP protocol to interact directly with the vulnerable Deployment component. By submitting crafted requests designed to exploit improper handling of deployment payloads or administrative functions, the attacker bypasses intended application boundaries. Because the component executes deployment tasks with the overarching system privileges of the application runtime, successful payload processing allows the attacker to execute arbitrary commands, manipulate internal application logic, or deploy malicious artifacts.\nThe post-exploitation impact is total system compromise. With complete control over Oracle Hyperion Profitability and Cost Management, the attacker achieves full read, write, and execute capabilities over sensitive corporate data stores, underlying file systems, and administrative interfaces. This ensures total loss of confidentiality through data exfiltration, integrity through unauthorized modification of cost and profitability calculations, and availability through operational sabotage or denial of service."
}
CVE-2026-70735: Oracle Hyperion Profitability Deployment Takeover (HIGH Severity, CVSS: 7.2) - Sceawere