Sceawere
Vulnerability Detail
CVE-2026-70794UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Reporting Integrity Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Reporting
- Attack Type
- Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-08-18T21:17:33.250Z",
"pubdate": "2026-08-18T21:17:33.250Z",
"executiveSummary": "An integrity vulnerability affecting the Oracle Hyperion Financial Reporting product, specifically within the Server component, allows a low-privileged authenticated attacker with logon access to the underlying infrastructure to compromise the application. The vulnerability is classified as difficult to exploit due to its high attack complexity requirements, yet successful exploitation grants unauthorized capabilities to create, delete, or modify critical data as well as any data accessible to Oracle Hyperion Financial Reporting.\nThe risk implication is focused strictly on data integrity, resulting in a CVSS 3.1 Base Score of 4.7 with a vector of CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N. The attack vector is local (AV:L), requiring the adversary to have prior interactive or programmatic logon access to the host execution environment. No user interaction (UI:N) is required, but the attack complexity remains high (AC:H), indicating that specific race conditions, precise timing, environmental preconditions, or multi-step execution sequences are necessary to achieve successful exploitation. Organizations running the affected version 11.2.25.0.000 face potential unauthorized tampering with sensitive financial reporting data, undermining data trustworthiness and regulatory compliance.",
"technicalDetails": "The vulnerability resides within the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. The root cause stems from improper handling of authorization controls, file system permissions, or insecure inter-process communication mechanisms accessible from the local infrastructure where the server executes. Because the threat model assumes a low-privileged local user (PR:L) with infrastructure logon capabilities, the attack surface involves local interfaces, shared resources, or improperly secured local daemons and configuration files utilized by the Hyperion Financial Reporting Server runtime environment.\nExploitation requires the attacker to first obtain a valid low-privileged operating system session on the host running the Oracle Hyperion Financial Reporting Server. From this local vantage point, the adversary must navigate high attack complexity (AC:H) constraints. This typically implies leveraging local privilege boundaries, exploiting race conditions during temporary file creation or inter-process messaging, manipulating insecurely permissioned configuration or data files, or abusing misconfigured service execution parameters that interface directly with the vulnerable Server component.\nThe step-by-step attack flow begins with the authenticated low-privileged user establishing an execution context on the target infrastructure. The attacker then prepares a specialized local payload or leverages local utilities to interact with the vulnerable Server component. Due to the high complexity requirement, the attacker must carefully orchestrate the attack sequence to bypass validation checks or exploit timing windows where data structures are processed insecurely. Once the conditions are successfully met, the payload executes against the target component, subverting internal trust boundaries.\nThe post-exploitation impact is localized to data integrity (I:H), allowing the adversary to execute unauthorized data manipulation operations. Specifically, the attacker can perform unauthorized creation, deletion, or modification of critical enterprise data and any auxiliary data accessible via the Oracle Hyperion Financial Reporting context. Confidentiality (C:N) and Availability (A:N) are unaffected according to the CVSS vector, meaning the attack does not result in information disclosure or denial of service conditions, but strictly compromises the authenticity and reliability of financial reports and underlying records managed by the application."
}