Sceawere
Vulnerability Detail
CVE-2026-70828UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Authorization Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.7
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.7",
"pubDate": "2026-08-18T21:17:37.970Z",
"pubdate": "2026-08-18T21:17:37.970Z",
"executiveSummary": "A security vulnerability has been identified within the Security component of the Oracle Hyperion Financial Management product, specifically affecting version 11.2.25.0.000. This vulnerability allows an authenticated attacker with low privileges and network access via the HTTP protocol to compromise the confidentiality of the target system. The flaw presents a significant risk due to its scope-changing nature, meaning that successful exploitation can extend beyond the immediate boundaries of Oracle Hyperion Financial Management to impact additional integrated or associated products. The primary impact of this vulnerability is directed entirely at data confidentiality, enabling unauthorized read access to critical enterprise data or complete unauthorized access to all data accessible via Oracle Hyperion Financial Management. The Common Vulnerability Scoring System (CVSS) version 3.1 assigns this issue a base score of 7.7, reflecting the severity of the potential information disclosure. Exploitation requires no user interaction and can be executed remotely over the network by an attacker who has successfully authenticated with low-level privileges, lowering the overall exploitation barrier once initial access is achieved.",
"technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000, stemming from inadequate access controls or improper authorization enforcement during request handling. The flaw is exposed via the HTTP protocol, allowing remote network-based attackers to interact with the vulnerable application endpoints. The attack surface is accessible to users possessing low privileges, indicating that standard, non-administrative user credentials are sufficient to initiate the exploitation sequence.\nThe attack flow begins when an attacker with low-level network access crafts and sends malicious HTTP requests targeted at the vulnerable Oracle Hyperion Financial Management Security component. Because the application fails to properly validate whether the authenticated low-privileged user is authorized to access specific functional domains or data repositories, the request bypasses intended security boundaries. Due to the scope-changing characteristic of this vulnerability (S:C in the CVSS vector), the execution context or authorization context shifts, potentially allowing the attacker to interact with resources outside the immediate administrative or functional sphere of the initial component.\nUpon successful processing of the malicious payload, the application improperly discloses sensitive information, leading to unauthorized access to critical data or complete extraction of all data accessible within the Oracle Hyperion Financial Management ecosystem. The vulnerability strictly affects confidentiality (C:H), resulting in a high impact on data privacy, while integrity (I:N) and availability (A:N) remain unaffected. No user interaction (UI:N) is required for the attack to succeed, and the attack complexity is evaluated as low (AC:L), meaning the exploitation vector is reliable and straightforward for an adversary with valid low-privileged credentials."
}