Sceawere
Vulnerability Detail
CVE-2026-70841UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Security Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.6
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.6",
"pubDate": "2026-08-18T21:17:39.730Z",
"pubdate": "2026-08-18T21:17:39.730Z",
"executiveSummary": "A security vulnerability has been identified within the Security component of the Oracle Hyperion Financial Management product, specifically affecting version 11.2.25.0.000. This vulnerability is classified as difficult to exploit and requires a low-privileged attacker to have local logon access to the underlying infrastructure where the Oracle Hyperion Financial Management application executes. Despite these prerequisites, successful exploitation results in a scope change that can significantly impact additional integrated products within the environment.\nThe primary risk associated with this vulnerability is the compromise of data confidentiality. Successful attacks enable unauthorized access to critical data or complete access to all data accessible by Oracle Hyperion Financial Management. The vulnerability carries a CVSS 3.1 Base Score of 5.6 with a vector indicating local attack vector, high attack complexity, low privileges required, no user interaction, and a changed security scope impacting confidentiality significantly while integrity and availability remain unaffected.",
"technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The root cause stems from insufficient security controls within the affected component, allowing a locally authenticated actor to leverage underlying infrastructure access to bypass authorization boundaries. Because the vulnerability involves a scope change (S:C), the security context transcends the immediate boundaries of Oracle Hyperion Financial Management, potentially exposing connected or dependent secondary products to security degradation.\nThe attack flow requires the adversary to first obtain low-privileged logon access to the host infrastructure executing Oracle Hyperion Financial Management. Due to the high attack complexity (AC:H), the attacker must orchestrate specific local conditions or execute precise operational sequences to successfully interact with the vulnerable Security component. Upon overcoming these procedural hurdles, the attacker can exploit the flaw without requiring user interaction (UI:N).\nPost-exploitation impact is strictly confined to confidentiality (C:H), resulting in unauthorized retrieval, exposure, or inspection of sensitive data repositories managed by Oracle Hyperion Financial Management or accessible via its operational context. Integrity (I:N) and availability (A:N) metrics are unaffected, indicating that the attacker cannot modify, delete, or disrupt application data or services through this specific vulnerability vector."
}