Sceawere
Vulnerability Detail
CVE-2026-70744UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Reporting Takeover Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Reporting
- Attack Type
- Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-08-18T21:17:27.227Z",
"pubdate": "2026-08-18T21:17:27.227Z",
"executiveSummary": "An unauthenticated, network-accessible vulnerability exists within the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. Classified as a high-severity flaw with a CVSS 3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), this vulnerability allows remote attackers to achieve complete system compromise without requiring user interaction or prior authentication.\nDespite the high attack complexity (AC:H) requirement, successful exploitation results in the total takeover of the affected Oracle Hyperion Financial Reporting product, granting the adversary full control over confidentiality, integrity, and availability. The risk implications are severe, as an end-to-end takeover can lead to unauthorized data exfiltration, systemic manipulation of financial reports, and severe operational disruption.\nOrganizations running the specified vulnerable version must prioritize immediate risk assessment and apply vendor-supplied patches or compensating controls to mitigate network-based exploitation vectors targeting the HTTP interface.",
"technicalDetails": "The vulnerability resides in the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. It exposes an attack surface accessible remotely via the HTTP protocol, allowing untrusted clients to interact directly with vulnerable application endpoints without authenticating.\nAlthough the CVSS v3.1 vector denotes an Attack Complexity of High (AC:H), indicating that specific race conditions, memory layouts, or chained conditions may be required for reliable exploitation, the lack of required privileges (PR:N) and user interaction (UI:N) broadens the threat landscape. An unauthenticated attacker positioned on the network can transmit maliciously crafted HTTP requests designed to target underlying weaknesses in request parsing, session handling, or object deserialization within the server logic.\nThe step-by-step attack flow begins with the adversary performing reconnaissance to locate the exposed Oracle Hyperion Financial Reporting HTTP service. Once identified, the attacker crafts a specialized payload delivered via HTTP. Upon receipt, the vulnerable server processes the input, where improper validation or handling leads to unauthorized memory corruption, privilege escalation, or remote code execution. Because the application runs with elevated system privileges, successful execution of the payload immediately yields complete control over the application environment.\nPost-exploitation impact includes full system takeover (C:H, I:H, A:H). The attacker can compromise sensitive financial data, alter business logic, deploy secondary backdoors, or disrupt core availability, severely undermining the integrity of financial reporting operations."
}