Sceawere

Vulnerability Detail

CVE-2026-70750UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Reporting Compromise

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Reporting
Attack Type
Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting.
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-18T21:17:27.787Z",
  "pubdate": "2026-08-18T21:17:27.787Z",
  "executiveSummary": "An easily exploitable vulnerability affects the Server component of Oracle Hyperion Financial Reporting, specifically version 11.2.25.0.000. This security flaw allows a low-privileged attacker who has obtained local logon access to the underlying infrastructure hosting the application to successfully compromise the entire Oracle Hyperion Financial Reporting environment.\nSuccessful exploitation of this vulnerability has severe risk implications, granting the adversary complete control over the affected system. The resulting impact compromises all three pillars of information security: confidentiality, integrity, and availability, leading to a total takeover of the Oracle Hyperion Financial Reporting instance.\nThe attack vector is classified as local, requiring the malicious actor to already possess low-privileged credentials and interactive or programmatic logon capabilities to the target host infrastructure. User interaction is not required for successful exploitation, and the attack complexity is assessed as low due to the straightforward nature of the prerequisites.",
  "technicalDetails": "The vulnerability resides within the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. Based on the provided CVSS 3.1 vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), the flaw allows local privilege escalation or unauthorized administrative manipulation of application resources by an authenticated low-privileged user.\nThe attack flow begins with the adversary establishing a valid session on the operating system infrastructure where the Oracle Hyperion Financial Reporting Server is deployed. Utilizing low-privileged access rights (PR:L) and operating locally (AV:L), the attacker interacts with vulnerable internal interfaces, misconfigured file permissions, insecure inter-process communication mechanisms, or unsecure service parameters managed by the application server component.\nBecause the attack complexity is low (AC:L) and no user interaction is required (UI:N), the malicious actor can execute arbitrary commands, manipulate critical application binaries or configuration files, or leverage insecure local execution contexts inherent to the vulnerable 11.2.25.0.000 build.\nUpon successful execution of the exploit vector, the payload behavior facilitates complete administrative escalation. The post-exploitation impact results in the total takeover of Oracle Hyperion Financial Reporting, allowing the adversary to read, modify, or destroy sensitive financial data (Confidentiality: High), tamper with application logic and reporting integrity (Integrity: High), and disrupt core reporting services (Availability: High) without altering the scope (S:U) of the underlying virtualization or hypervisor layer."
}
CVE-2026-70750: Oracle Hyperion Financial Reporting Compromise (HIGH Severity, CVSS: 7.8) - Sceawere