Sceawere

Vulnerability Detail

CVE-2026-70842UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.4
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.4",
  "pubDate": "2026-08-18T21:17:39.870Z",
  "pubdate": "2026-08-18T21:17:39.870Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. This security flaw allows a low-privileged threat actor with valid local logon access to the underlying infrastructure where the product executes to compromise the application entirely. Successful exploitation of this vulnerability alters the security scope, potentially resulting in significant impacts on additional integrated products within the environment.\nThe primary risk implications involve severe compromises to data confidentiality and integrity. Successful attacks grant unauthorized read, creation, deletion, and modification capabilities over critical data or the entirety of accessible Oracle Hyperion Financial Management data. The Common Vulnerability Scoring System (CVSS) 3.1 assigns this issue a base score of 8.4, reflecting the high severity of the potential impact on both confidentiality and integrity.\nExploitation requirements are constrained by the necessity for local infrastructure access and low-privileged authentication, meaning the attacker must already possess internal footing on the host executing the vulnerable software. However, the low attack complexity and the absence of user interaction make the execution path straightforward for an authenticated insider or an adversary who has achieved initial compromise of the host operating system.",
  "technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The root cause stems from insufficient access controls, insecure permission assignments, or improper boundary enforcement within the application architecture running locally on the infrastructure. Because the flaw allows a low-privileged user interacting with the host OS to manipulate security boundaries, the operational scope changes from local infrastructure access to broader systemic compromise across dependent services.\nThe attack flow begins when an authenticated threat actor leverages low-privileged access to the local infrastructure housing the Oracle Hyperion Financial Management deployment. Utilizing the inherent flaws in the Security component, the attacker bypasses intended authorization checks enforced by the application. This is achieved by interacting directly with vulnerable internal execution vectors, insecure APIs, or misconfigured file system objects and registry keys associated with the product's security context.\nPost-exploitation impact is characterized by unauthorized data manipulation and disclosure. Once the security restrictions are bypassed, the attacker gains the ability to compromise critical data assets managed by Oracle Hyperion Financial Management. This includes unauthorized creation, deletion, or modification of sensitive financial data, as well as full read access to all data repositories accessible to the application. Furthermore, due to the scope change vector, the compromise can cascade to impact additional adjacent products integrated within the enterprise architecture.\nAuthentication and privilege requirements dictate that the attacker must possess valid local logon credentials to the target infrastructure and low-privileged execution rights. The attack vector is strictly local (AV:L), meaning network exposure is not required for initial exploitation. The attack complexity is low (AC:L), and no user interaction (UI:N) is mandated, allowing automated or direct execution by the rogue user once local access is established."
}
CVE-2026-70842: Oracle Hyperion Financial Management Privilege Escalation Vulnerability (HIGH Severity, CVSS: 8.4) - Sceawere