Sceawere

Vulnerability Detail

CVE-2026-70740UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Reporting Takeover

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Reporting
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-18T21:17:26.780Z",
  "pubdate": "2026-08-18T21:17:26.780Z",
  "executiveSummary": "A critical security vulnerability has been identified within the Oracle Hyperion Financial Reporting product, specifically residing in the Server component. This remotely exploitable flaw affects version 11.2.25.0.000 and poses severe risk to organizational infrastructure due to its capability to facilitate complete system compromise. The vulnerability is classified with a maximum CVSS 3.1 Base Score of 9.8, reflecting high severity impacts across confidentiality, integrity, and availability metrics with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.\nThe flaw allows unauthenticated malicious actors with network accessibility via HTTP to target the vulnerable server without requiring any user interaction or prior privileges. Successful exploitation results in the total takeover of the Oracle Hyperion Financial Reporting application, enabling unauthorized entities to execute arbitrary actions, manipulate or exfiltrate sensitive financial data, and disrupt critical business operations. The absence of authentication and privilege requirements, combined with low attack complexity over standard network protocols, elevates the urgency for defensive intervention and remediation across all deployed instances of the affected software version.",
  "technicalDetails": "The vulnerability resides within the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. It manifests as a remotely accessible flaw exposed via the HTTP protocol, lacking proper input validation, access controls, or authentication mechanisms required to secure sensitive server-side operations against unauthorized requests.\nThe attack flow begins when an unauthenticated adversary crafts a malicious HTTP request directed at the network-exposed endpoints of the vulnerable Oracle Hyperion Financial Reporting Server. Because the application fails to enforce authentication or privileges (PR:N, UI:N), the request is processed directly by the vulnerable component without verifying the identity or authorization level of the sender (AV:N, AC:L).\nUpon receiving the malicious payload, the vulnerable server executes the unintended operations or processes unauthorized inputs, leading to memory corruption, improper command execution, or authorization bypasses depending on the exact internal handling mechanism. This allows the attacker to subvert the application logic entirely.\nPost-exploitation impact encompasses the complete takeover of the Oracle Hyperion Financial Reporting environment (S:U, C:H, I:H, A:H). An attacker achieving successful exploitation gains full administrative control over the application tier, enabling them to read, modify, or delete confidential financial data, inject persistent backdoors, pivot deeper into the internal corporate network, or render the reporting service entirely unavailable to legitimate enterprise users."
}
CVE-2026-70740: Oracle Hyperion Financial Reporting Takeover (CRITICAL Severity, CVSS: 9.8) - Sceawere