Sceawere

Vulnerability Detail

CVE-2026-70823UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Security Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.4
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.4",
  "pubDate": "2026-08-18T21:17:37.303Z",
  "pubdate": "2026-08-18T21:17:37.303Z",
  "executiveSummary": "A vulnerability exists within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000, presenting significant risk to enterprise financial systems. This security flaw is categorized as difficult to exploit but allows an unauthenticated remote attacker with network access via HTTPS to compromise the targeted application. Successful exploitation of this vulnerability has severe business and operational implications, resulting in unauthorized creation, deletion, or modification access to critical data, alongside unauthorized or complete read access to all Oracle Hyperion Financial Management accessible data. The Common Vulnerability Scoring System version 3.1 assigns this issue a Base Score of 7.4 with a vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N, reflecting high impacts on confidentiality and integrity without affecting system availability. The attack vector is strictly network-based, requiring no user interaction or prior privileges, though the high attack complexity indicates that specific conditions or synchronization requirements must be met by the threat actor to achieve successful compromise.",
  "technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The affected product exposes administrative or sensitive operational endpoints over HTTPS that fail to properly enforce access controls or validate request integrity under specific conditions, allowing bypass of security boundaries. The attack vector is strictly network-based (AV:N), meaning that any remote entity capable of routing packets to the target web application interface can attempt exploitation. Crucially, the vulnerability requires no authentication (PR:N) and no user interaction (UI:N), lowering the barrier for external threat actors once initial reconnaissance is complete. However, the attack complexity is rated as high (AC:H), implying that successful exploitation necessitates nuanced reconnaissance, precise timing, race conditions, or specific environmental prerequisites to bypass the security mechanisms protecting the underlying data stores. The scope remains unchanged (S:U), indicating that the vulnerability impacts only the resources managed directly by the vulnerable Oracle Hyperion Financial Management component rather than extending to the underlying host operating system or out-of-scope hypervisor layers. During the attack flow, an unauthenticated adversary crafts specialized HTTPS requests directed at the vulnerable Security component. Due to the flaw in request processing or access validation, the application processes the malicious payload without verifying whether the source possesses the requisite authorization. Upon successful execution of the exploit sequence, the attacker achieves unauthorized read, write, and deletion capabilities over critical data repositories. The confidentiality impact is high (C:H), granting the adversary complete access to all accessible financial records, proprietary metrics, and sensitive metadata stored within the Oracle Hyperion Financial Management ecosystem. Concurrently, the integrity impact is high (I:H), enabling unauthorized data manipulation, including the creation of fraudulent records, modification of existing financial entries, or deletion of critical audit trails and application data. Availability remains unimpacted (A:N), as the attack methodology focuses on data compromise and manipulation rather than denial-of-service conditions."
}
CVE-2026-70823: Oracle Hyperion Financial Management Security Vulnerability (HIGH Severity, CVSS: 7.4) - Sceawere