Sceawere

Vulnerability Detail

CVE-2026-70736UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Profitability Deployment Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Profitability and Cost Management
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Profitability and Cost Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Profitability and Cost Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-18T21:17:26.330Z",
  "pubdate": "2026-08-18T21:17:26.330Z",
  "executiveSummary": "A security vulnerability has been identified within the Deployment component of Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000, presenting significant risk to enterprise data assets. This remotely exploitable flaw allows an authenticated attacker with low privileges and network access via HTTP to compromise the target application without requiring user interaction.\nSuccessful exploitation of this vulnerability has severe implications for data security, granting unauthorized read access to critical data and potentially complete access to all data accessible by Oracle Hyperion Profitability and Cost Management. Additionally, the vulnerability permits unauthorized write capabilities, specifically enabling unauthorized update, insert, or delete operations against a subset of the application's accessible data repositories.\nRated with a CVSS 3.1 Base Score of 7.1, the vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N) highlights high confidentiality impact and low integrity impact, with no effect on availability. The low attack complexity and network vector make this vulnerability an appealing target for malicious actors possessing baseline credentials, underscoring the necessity for prompt remediation and stringent access control enforcement within affected enterprise environments.",
  "technicalDetails": "The vulnerability resides in the Deployment component of Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000. The underlying root cause stems from insufficient authorization checks and improper input validation handling within network-exposed HTTP endpoints, failing to adequately enforce access control boundaries between low-privileged users and sensitive administrative or operational data operations.\nExploitation requires the attacker to possess low-privileged network access to the application via the HTTP protocol. Because the attack vector is network-based (AV:N) and attack complexity is low (AC:L), an adversary with standard user credentials can craft malicious HTTP requests directed at vulnerable deployment functions. The absence of strict user interaction requirements (UI:N) facilitates automated or scripted exploitation phases once initial authentication is established.\nThe attack flow proceeds as follows: First, the low-privileged attacker authenticates to the Oracle Hyperion Profitability and Cost Management environment using valid baseline credentials. Second, the attacker formulates specifically crafted HTTP payloads targeted at the Deployment component endpoints. Third, due to inadequate server-side enforcement of privilege levels and authorization parameters, the application processes the request, bypassing intended security boundaries.\nUpon successful execution of the attack payload, the post-exploitation impact manifests across two primary vectors: confidentiality and integrity. For confidentiality, the attacker gains unauthorized read access to critical data sets and potentially complete access to all data accessible by the application instance, exposing sensitive financial and cost management intelligence. For integrity, the attacker achieves unauthorized modification capabilities, allowing them to execute update, insert, or delete operations on a subset of the application's accessible data, thereby risking data corruption, unauthorized tampering, and business logic disruption."
}
CVE-2026-70736: Oracle Hyperion Profitability Deployment Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere