Sceawere

Vulnerability Detail

CVE-2026-70854UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Security Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-18T21:17:41.480Z",
  "pubdate": "2026-08-18T21:17:41.480Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. This security flaw allows unauthenticated remote attackers with network access via the HTTP protocol to compromise the targeted application.\nSuccessful exploitation of this vulnerability does not require user interaction and grants unauthorized actors the ability to perform creation, deletion, or modification operations on critical data and all accessible data within Oracle Hyperion Financial Management. Furthermore, attackers can induce a complete denial of service (DoS) state, leading to application hangs or frequently repeatable crashes.\nThe severity of this issue is underscored by a CVSS 3.1 Base Score of 9.1, driven by high impacts to both data integrity and system availability, while confidentiality remains unaffected. The CVSS vector is designated as (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).\nGiven the lack of authentication and privilege requirements combined with remote network vector exposure, this vulnerability poses severe operational and data integrity risks to organizations deploying the affected version, necessitating immediate defensive prioritization.",
  "technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management, specifically affecting version 11.2.25.0.000. The underlying root cause stems from insufficient validation, authorization, or boundary enforcement mechanisms within the HTTP request processing logic managed by the vulnerable component.\nExploitation is conducted remotely over the network using standard HTTP protocols. Because the vulnerability requires low attack complexity, no prior authentication, and no user interaction, an external threat actor can directly target the exposed HTTP endpoints associated with the Oracle Hyperion Financial Management Security component.\nThe step-by-step attack flow typically proceeds as follows: First, the unauthenticated attacker crafts a malicious HTTP request designed to interact with the vulnerable Security component handlers. Second, the attacker transmits this payload across the network to the exposed Oracle Hyperion Financial Management instance. Third, due to inadequate input handling or access control enforcement within the component, the application processes the malicious payload, bypassing intended security gates.\nUpon successful processing, the payload executes unauthorized data manipulation routines, permitting the adversary to create, modify, or delete critical financial and administrative data stored or managed by Oracle Hyperion Financial Management. Concurrently or alternatively, the malicious input can trigger resource exhaustion, exception handling failures, or memory corruption within the application process, resulting in a complete denial of service characterized by application hangs or repeatable crashes.\nThe scope of the vulnerability is unchanged (S:U), meaning the impact is constrained to the Oracle Hyperion Financial Management product itself, but the consequences within that boundary are severe, completely compromising integrity and availability parameters."
}
CVE-2026-70854: Oracle Hyperion Financial Management Security Vulnerability (CRITICAL Severity, CVSS: 9.1) - Sceawere