Sceawere
Vulnerability Detail
CVE-2026-70784UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Reporting Compromise
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Reporting
- Attack Type
- Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-18T21:17:31.807Z",
"pubdate": "2026-08-18T21:17:31.807Z",
"executiveSummary": "An elevation of privilege and data manipulation vulnerability has been identified within the Oracle Hyperion Financial Reporting product, specifically residing in the Server component at version 11.2.25.0.000. This vulnerability allows an authenticated attacker with low privileges and local logon access to the underlying host infrastructure to compromise the application.\nSuccessful exploitation of this flaw requires high attack complexity and grants the adversary unauthorized capabilities, including the creation, deletion, and modification of critical or accessible data, alongside unauthorized read access to a subset of sensitive data. The confidentiality and integrity of the application state are directly impacted, while system availability remains unaffected.\nGiven the requirement for local infrastructure access and high attack complexity, organizations must enforce strict access controls and principle of least privilege methodologies on hosts executing the affected server software to mitigate potential risk.",
"technicalDetails": "The vulnerability affects the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. It is classified as an infrastructure-level compromise vector characterized by a CVSS 3.1 Base Score of 5.3 with the vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N.\nThe attack vector is local (AV:L), meaning the adversary must already possess logon access to the operating system or infrastructure where the Oracle Hyperion Financial Reporting Server is deployed and executing. Network exposure is absent, precluding remote exploitation. Furthermore, the attack complexity is rated as high (AC:H), indicating that specific race conditions, environmental configurations, or precise timing mechanisms are necessary for successful exploitation.\nThe attacker is required to hold low privileges (PR:L) on the host system, meaning standard user accounts with local interactive or shell access can potentially initiate the attack chain without requiring administrative or root elevation at the onset. No user interaction (UI:N) is required by other operators during the execution phase.\nThe attack flow proceeds as follows: First, the authenticated low-privileged user interacts locally with the infrastructure running the Oracle Hyperion Financial Reporting Server. Leveraging internal misconfigurations, insecure file permissions, or flawed inter-process communication mechanisms inherent to the vulnerable 11.2.25.0.000 deployment, the attacker navigates the execution boundary. Due to high attack complexity, the attacker must manipulate local system states to interact with the vulnerable Server component functions.\nUpon successful execution of the attack payload, the adversary bypasses intended access control boundaries enforced by Oracle Hyperion Financial Reporting. This grants unauthorized write, creation, and deletion capabilities over critical enterprise data managed by the application, leading to severe integrity violations. Additionally, the attacker gains unauthorized read access to a specific subset of confidential reporting data, breaching data confidentiality. The scope (S:U) remains unchanged, as the security impact is contained within the boundaries of the vulnerable application component and its directly accessible data stores."
}