Sceawere
Vulnerability Detail
CVE-2026-70838UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Security Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-08-18T21:17:39.330Z",
"pubdate": "2026-08-18T21:17:39.330Z",
"executiveSummary": "A security vulnerability has been identified in the Oracle Hyperion Financial Management product within the Security component, specifically affecting version 11.2.25.0.000. This vulnerability is classified as an easily exploitable flaw that can be leveraged by a low-privileged attacker who has obtained local logon access to the underlying infrastructure where Oracle Hyperion Financial Management executes.\nSuccessful exploitation of this vulnerability compromises the target application, leading to severe confidentiality and integrity impacts. An attacker can achieve unauthorized access to critical data, obtain complete access to all data accessible by Oracle Hyperion Financial Management, and execute unauthorized update, insert, or delete operations on a subset of the accessible data.\nThe severity of this issue is underscored by a CVSS 3.1 Base Score of 6.1, with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N. The risk implications include the potential exposure of sensitive financial records and the compromise of data integrity through unauthorized modifications. Exploitation requirements necessitate local access to the host infrastructure alongside low-privileged credentials, while requiring no user interaction.",
"technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The root cause stems from insufficient access controls or improper handling of security boundaries within the affected component, which permits a user with limited privileges to transcend their assigned authorization limits locally.\nThe attack vector is classified as Local (AV:L), meaning the adversary must first establish an interactive or programmatic logon session on the specific infrastructure hosting the Oracle Hyperion Financial Management deployment. The attack complexity is rated as Low (AC:L), indicating that the exploitation path lacks significant hurdles or specialized conditions once the local environment is reached. Furthermore, the vulnerability requires Low privileges (PR:L), signifying that standard, authenticated system or application users can initiate the attack without administrative or elevated access rights. No user interaction (UI:N) is required for successful exploitation.\nThe step-by-step attack flow begins with the low-privileged attacker authenticating to the underlying host infrastructure through standard operating system logon mechanisms. Once inside the environment, the attacker interacts directly or indirectly with the vulnerable Oracle Hyperion Financial Management Security component. Because the component fails to properly enforce privilege boundaries or validate the execution context of the local user, the attacker is able to bypass intended security restrictions.\nPost-exploitation impact encompasses unauthorized data disclosure and manipulation. Specifically, the confidentiality impact is High (C:H), allowing the adversary to read critical financial data and gain total visibility over all data repositories accessible by the application. The integrity impact is Low (I:L), enabling the attacker to perform unauthorized insert, update, or delete actions against specific subsets of accessible data. The availability impact remains unaffected (A:N), as the attack vectors described do not inherently cause denial-of-service conditions or system crashes."
}