Sceawere
Vulnerability Detail
CVE-2026-70750UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Reporting Compromise
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Reporting
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting.
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-08-18T21:17:27.787Z",
"pubdate": "2026-08-18T21:17:27.787Z",
"executiveSummary": "An easily exploitable vulnerability affects the Server component of Oracle Hyperion Financial Reporting, specifically version 11.2.25.0.000. This security flaw allows a low-privileged attacker who has obtained local logon access to the underlying infrastructure hosting the application to successfully compromise the entire Oracle Hyperion Financial Reporting environment.\nSuccessful exploitation of this vulnerability has severe risk implications, granting the adversary complete control over the affected system. The resulting impact compromises all three pillars of information security: confidentiality, integrity, and availability, leading to a total takeover of the Oracle Hyperion Financial Reporting instance.\nThe attack vector is classified as local, requiring the malicious actor to already possess low-privileged credentials and interactive or programmatic logon capabilities to the target host infrastructure. User interaction is not required for successful exploitation, and the attack complexity is assessed as low due to the straightforward nature of the prerequisites.",
"technicalDetails": "The vulnerability resides within the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. Based on the provided CVSS 3.1 vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), the flaw allows local privilege escalation or unauthorized administrative manipulation of application resources by an authenticated low-privileged user.\nThe attack flow begins with the adversary establishing a valid session on the operating system infrastructure where the Oracle Hyperion Financial Reporting Server is deployed. Utilizing low-privileged access rights (PR:L) and operating locally (AV:L), the attacker interacts with vulnerable internal interfaces, misconfigured file permissions, insecure inter-process communication mechanisms, or unsecure service parameters managed by the application server component.\nBecause the attack complexity is low (AC:L) and no user interaction is required (UI:N), the malicious actor can execute arbitrary commands, manipulate critical application binaries or configuration files, or leverage insecure local execution contexts inherent to the vulnerable 11.2.25.0.000 build.\nUpon successful execution of the exploit vector, the payload behavior facilitates complete administrative escalation. The post-exploitation impact results in the total takeover of Oracle Hyperion Financial Reporting, allowing the adversary to read, modify, or destroy sensitive financial data (Confidentiality: High), tamper with application logic and reporting integrity (Integrity: High), and disrupt core reporting services (Availability: High) without altering the scope (S:U) of the underlying virtualization or hypervisor layer."
}