Sceawere
Vulnerability Detail
CVE-2026-70914UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Takeover Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management.
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.0",
"pubDate": "2026-08-18T21:17:49.223Z",
"pubdate": "2026-08-18T21:17:49.223Z",
"executiveSummary": "An unauthenticated security vulnerability affects the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000.\nThis vulnerability is classified as difficult to exploit and can result in the complete takeover of the Oracle Hyperion Financial Management application, impacting confidentiality, integrity, and availability with a CVSS 3.1 base score of 7.0.\nSuccessful exploitation requires the attacker to have logon access to the underlying infrastructure where Oracle Hyperion Financial Management executes, as well as mandatory human interaction from a user other than the attacker.\nThe risk implications are severe due to the potential total compromise of the affected product, allowing unauthorized control over critical financial management systems and sensitive data assets.\nDefenders must account for the local access vector and the requirement for social engineering or user assistance when assessing risk and prioritizing remediation efforts for this specific advisory.",
"technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000.\nThe attack vector is local (AV:L), meaning the adversary must already possess logon capabilities to the underlying infrastructure hosting the Oracle Hyperion Financial Management execution environment.\nThe attack complexity is rated as high (AC:H), indicating that successful execution requires specific conditions, race conditions, or complex preparatory steps by the adversary.\nAuthentication is not required (PR:N) at the application layer to initiate the attack, though local infrastructure access is a prerequisite.\nA critical prerequisite for successful exploitation is human interaction (UI:R) from a distinct individual other than the attacker, suggesting the reliance on a victim executing a specific local action or interacting with a manipulated interface or process.\nThe scope remains unchanged (S:U), meaning the impact is constrained to the Oracle Hyperion Financial Management vulnerability domain rather than extending to secondary security authorities or hypervisor layers.\nUpon successful exploitation, the impact affects confidentiality, integrity, and availability (C:H/I:H/A:H) at a high level, culminating in the complete takeover of the Oracle Hyperion Financial Management instance.\nThe step-by-step attack flow involves the unauthenticated attacker establishing local access to the host infrastructure, staging malicious payloads or manipulating local execution parameters, and subsequently engineering a scenario where another user interacts with the system in a manner that triggers the vulnerable Security component, ultimately granting the attacker administrative or execution control over the target application."
}