Sceawere

Vulnerability Detail

CVE-2026-70738UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Profitability and Cost Management Authorization Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Profitability and Cost Management
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Profitability and Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Profitability and Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-18T21:17:26.553Z",
  "pubdate": "2026-08-18T21:17:26.553Z",
  "executiveSummary": "An authorization vulnerability exists within the Deployment component of Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000. This security flaw enables authenticated attackers with low privileges and network access via the HTTP protocol to compromise the affected application. Successful exploitation of this vulnerability compromises data confidentiality and integrity by permitting unauthorized access to critical data, as well as unauthorized creation, deletion, or modification of all data accessible within Oracle Hyperion Profitability and Cost Management.\nThe vulnerability carries a CVSS 3.1 Base Score of 8.1 with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N. The risk implications are severe for organizations utilizing the affected software, as unauthorized modification or disclosure of financial, profitability, and cost management data can lead to regulatory non-compliance, financial misreporting, and business disruption. The attack vector is strictly network-based, requires low complexity, and does not require user interaction, though it mandates that the malicious actor possesses low-privileged valid credentials within the system.",
  "technicalDetails": "The vulnerability resides in the Deployment component of Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000. The root cause stems from insufficient authorization checks and access control enforcement within server-side request handlers processing HTTP requests. Specifically, the application fails to adequately validate whether a low-privileged authenticated user possesses the necessary administrative or operational permissions to interact with specific deployment functionalities and backend data repositories.\nExploitation of this vulnerability occurs over the network using the HTTP protocol. An attacker begins by authenticating to the Oracle Hyperion Profitability and Cost Management application with low-privileged credentials. Once authenticated, the attacker crafts malicious HTTP requests targeting the vulnerable Deployment component. Because the application fails to properly enforce access controls, the server processes these requests without verifying whether the requesting user is authorized to perform administrative data manipulation or retrieval actions.\nThe attack flow proceeds as follows: First, the low-privileged attacker maps the application endpoints associated with the Deployment component. Second, the attacker formulates custom HTTP requests designed to bypass interface restrictions or directly invoke backend deployment functions. Third, upon receipt of the request, the vulnerable component executes the requested operations—such as reading, writing, deleting, or modifying critical profitability and cost management data—under the context of the application's service principal. Finally, the system returns the sensitive data to the attacker or completes the unauthorized data modification without validating the user's role or privilege level.\nThe post-exploitation impact includes complete compromise of confidentiality and integrity for all data accessible within Oracle Hyperion Profitability and Cost Management. The attacker can exfiltrate sensitive financial calculations and cost models, or maliciously inject, alter, and delete critical records, thereby corrupting the integrity of the enterprise's profitability analytics."
}
CVE-2026-70738: Oracle Hyperion Profitability and Cost Management Authorization Vulnerability (HIGH Severity, CVSS: 8.1) - Sceawere