Sceawere
Vulnerability Detail
CVE-2026-70916UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.0",
"pubDate": "2026-08-18T21:17:49.357Z",
"pubdate": "2026-08-18T21:17:49.357Z",
"executiveSummary": "An unauthenticated information disclosure vulnerability exists within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000, allowing an attacker with local execution access to compromise sensitive data. This security flaw enables unauthorized read access to a specific subset of data accessible by the Oracle Hyperion Financial Management application. The vulnerability carries a CVSS 3.1 Base Score of 4.0, indicating a targeted confidentiality impact without affecting system integrity or availability. Exploitation requires the attacker to possess logon access to the underlying infrastructure where the affected product executes, meaning remote exploitation over a network vector is not feasible without prior local access. Successful exploitation exposes proprietary financial or system-related data to unauthorized entities, potentially facilitating further reconnaissance or secondary compromise of interconnected systems within the enterprise environment. Organizations utilizing the impacted version must evaluate access controls and infrastructure hardening to mitigate potential unauthorized data exposure risks.",
"technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management, specifically affecting version 11.2.25.0.000. According to the CVSS 3.1 vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N), the attack vector is Local (AV:L), meaning the adversary must interact with the target infrastructure directly or via existing local execution capabilities. The attack complexity is rated as Low (AC:L), indicating that no specialized race conditions or complex exploitation prerequisites are required once the initial infrastructure access is established. Privilege requirements are None (PR:N) from the perspective of the application's internal access controls, though system-level logon access is a baseline prerequisite. User interaction is not required (UI:N), allowing automated or direct execution of the exploit vector without social engineering.\nThe root cause stems from insufficient access controls or improper handling of authorization boundaries within the Security component during local execution contexts. This flaw permits unauthenticated processes or users operating on the host infrastructure to query, traverse, or read data stores and sensitive application resources that should otherwise be restricted. The attack flow begins with the adversary securing logon access to the host operating system or infrastructure layer hosting the Oracle Hyperion Financial Management deployment. Subsequently, the attacker leverages local execution pathways, system utilities, or direct file system/memory inspection techniques targeting the vulnerable Security component. Because the application fails to adequately validate the authenticity or authorization of the local accessor requesting specific data subsets, the underlying mechanism returns the requested information.\nThe post-exploitation impact is strictly constrained to confidentiality loss (C:L), resulting in unauthorized read access to a subset of data managed by Oracle Hyperion Financial Management. Integrity (I:N) and Availability (A:N) vectors remain unaffected, meaning the vulnerability does not allow data modification, deletion, denial of service, or arbitrary code execution. The scope remains unchanged (S:U), as the vulnerability's impact is contained within the immediate application context without escalating privileges across security domains or hypervisor boundaries."
}