Sceawere

Vulnerability Detail

CVE-2026-70767UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Reporting Unauthorized Data Access

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Reporting
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T21:17:29.420Z",
  "pubdate": "2026-08-18T21:17:29.420Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. This security flaw allows a remote attacker with low privileges and network access via the HTTP protocol to compromise the affected application.\nSuccessful exploitation of this vulnerability results in unauthorized access to critical data or complete access to all data accessible within Oracle Hyperion Financial Reporting, severely impacting confidentiality.\nThe vulnerability carries a CVSS 3.1 Base Score of 6.5 with a vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating that no user interaction is required and the attack complexity is low, provided the adversary possesses valid low-privileged credentials and network connectivity to the target service.",
  "technicalDetails": "The vulnerability resides in the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. The underlying root cause involves improper authorization enforcement or inadequate access control validation within the request handling logic of the HTTP service.\nAttackers with network access can interact directly with the vulnerable HTTP endpoints exposed by the Oracle Hyperion Financial Reporting Server. Because the system fails to adequately verify whether an authenticated, low-privileged user possesses the necessary authorization to request specific financial reports or sensitive data repositories, unauthorized read operations can be performed.\nThe attack flow proceeds as follows: First, the low-privileged attacker establishes a network connection to the target server utilizing the HTTP protocol. Second, the attacker crafts and transmits malicious or unauthorized HTTP requests targeting sensitive reporting endpoints or data retrieval functions. Third, due to insufficient privilege validation checks within the server-side component, the application processes the request and bypasses intended access restrictions. Finally, the server returns the requested critical financial data to the attacker, resulting in a severe breach of confidentiality without affecting data integrity or system availability."
}
CVE-2026-70767: Oracle Hyperion Financial Reporting Unauthorized Data Access (MEDIUM Severity, CVSS: 6.5) - Sceawere