Sceawere

Vulnerability Detail

CVE-2026-70840UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Security Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.4
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.4",
  "pubDate": "2026-08-18T21:17:39.597Z",
  "pubdate": "2026-08-18T21:17:39.597Z",
  "executiveSummary": "An easily exploitable security vulnerability affects the Oracle Hyperion Financial Management product within the Security component, specifically targeting version 11.2.25.0.000. This vulnerability allows a low-privileged attacker who possesses local logon access to the underlying infrastructure where the application executes to compromise the entire Oracle Hyperion Financial Management environment. Although the primary vulnerability resides within Oracle Hyperion Financial Management, successful exploitation introduces a significant scope change, indicating that attacks may severely impact additional auxiliary products and shared infrastructure resources. Successful exploitation of this flaw grants the adversary unauthorized capabilities, including the creation, deletion, and modification of critical data, as well as complete unauthorized read access to all accessible Oracle Hyperion Financial Management data repositories. The vulnerability carries a CVSS 3.1 Base Score of 8.4, reflecting severe confidentiality and integrity impacts. The CVSS vector is defined as CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N, highlighting that the attack vector is local, attack complexity is low, low privileges are required, and user interaction is not necessary for successful compromise.",
  "technicalDetails": "The vulnerability manifests within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The root cause stems from improper access controls, permission management, or insecure handling of local resources and security contexts within the execution environment. Because the attack vector is local (AV:L), the threat actor must first establish interactive logon access to the host infrastructure hosting the Oracle Hyperion Financial Management deployment. The requirement for attack complexity is low (AC:L), meaning the conditions or steps required to exploit the flaw are straightforward and dependable for an authenticated low-privileged user (PR:L). No user interaction (UI:N) is required to trigger or facilitate the exploitation flow, allowing the attacker to execute the attack deterministically.\nThe attack flow begins with the low-privileged attacker authenticating locally to the host operating system or infrastructure tier where Oracle Hyperion Financial Management services operate. Leveraging the insecure design or misconfigured permissions within the Security component, the attacker interacts with vulnerable local binaries, configuration stores, or inter-process communication mechanisms. By supplying malicious inputs or manipulating local execution contexts, the attacker bypasses standard authorization boundaries enforced by the application.\nDue to the scope change (S:C) characteristic of this vulnerability, the compromise is not strictly contained within the boundaries of the Oracle Hyperion Financial Management application instance. Instead, privileges and access gained locally propagate across associated trust zones, potentially impacting integrated or co-located products within the enterprise infrastructure. The post-exploitation impact is severe regarding data integrity and confidentiality (C:H/I:H/A:N). The attacker gains unauthorized authorization to read, create, modify, or delete critical business datasets, financial records, and operational information stored within or accessible by Oracle Hyperion Financial Management, while availability remains unaffected."
}
CVE-2026-70840: Oracle Hyperion Financial Management Security Privilege Escalation Vulnerability (HIGH Severity, CVSS: 8.4) - Sceawere