Sceawere

Vulnerability Detail

CVE-2026-70776UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Reporting Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
2.6
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Reporting
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data.
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 2.6 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.6",
  "pubDate": "2026-08-18T21:17:30.613Z",
  "pubdate": "2026-08-18T21:17:30.613Z",
  "executiveSummary": "A vulnerability exists within the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000, presenting risks to data integrity. This security flaw can be leveraged by a low-privileged threat actor with network access via HTTP to compromise the targeted application. Successful exploitation of this vulnerability is classified as difficult and introduces strict prerequisites, specifically requiring human interaction from an individual other than the attacker. Upon successful execution, the attack grants unauthorized capabilities limited to updating, inserting, or deleting accessible data within Oracle Hyperion Financial Reporting. The vulnerability carries a CVSS 3.1 base score of 2.6 with an impact exclusively affecting data integrity, resulting in no direct risks to system confidentiality or availability. The combination of network exposure, required low-level authentication, and necessary victim interaction shapes the overall risk profile and dictates targeted defensive postures.",
  "technicalDetails": "The identified vulnerability resides within the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. The attack vector is strictly network-based, utilizing the HTTP protocol to interact with the vulnerable application interface. Exploitation complexity is rated as high, indicating that successful execution requires specific conditions or non-trivial manipulation by the adversary. Privilege requirements mandate that the attacker possess low-level authentication credentials within the system prior to attempting exploitation. Additionally, successful attack chains demand explicit human interaction from a user other than the attacker, typically manifesting as social engineering vectors or victim-assisted navigation of malicious inputs or workflows. The post-exploitation impact is constrained to the integrity vector, enabling unauthorized modification, insertion, or deletion of data accessible to the affected Oracle Hyperion Financial Reporting instance, while leaving confidentiality and availability uncompromised. The step-by-step attack flow begins with the authenticated low-privileged attacker preparing a crafted HTTP request or payload designed to abuse the vulnerable server-side logic. The attacker then induces the required human interaction, compelling a secondary user to execute or load the malicious sequence within their authenticated session. Upon interaction, the server processes the incoming request without adequate validation or authorization checks regarding the scope of data modification permitted for the initiating context. Consequently, the application executes the unauthorized data update, insertion, or deletion operations against the accessible data repository, achieving the intended integrity violation."
}
CVE-2026-70776: Oracle Hyperion Financial Reporting Vulnerability (LOW Severity, CVSS: 2.6) - Sceawere