Sceawere

Vulnerability Detail

CVE-2026-70920UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Takeover Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-08-18T21:17:49.810Z",
  "pubdate": "2026-08-18T21:17:49.810Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000, presenting critical risks to organizational security postures. The vulnerability allows a low-privileged remote attacker with network access via SQL to execute unauthorized database-level interactions that compromise the integrity, confidentiality, and availability of the target application.\nSuccessful exploitation of this security flaw results in a complete takeover of Oracle Hyperion Financial Management. Furthermore, the vulnerability exhibits a scope change, meaning that successful attacks are not strictly contained within the primary affected product but may significantly impact additional integrated products and underlying infrastructure components.\nThe CVSS 3.1 base score is rated at an exceptionally high 9.9, reflecting the severity of potential impacts across confidentiality, integrity, and availability vectors. The attack vector is network-based (AV:N), attack complexity is low (AC:L), user interaction is not required (UI:N), and the required privileges are low (PR:L). Given the low prerequisites and devastating potential impact, immediate defensive prioritization and mitigation deployment are strongly advised for all environments running the affected version.",
  "technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management, specifically affecting version 11.2.25.0.000. The root cause stems from improper input validation and insufficient sanitization of SQL-based queries handled by the application logic during security processing routines.\nAn attacker initiates the attack flow by leveraging network access to interact with the Oracle Hyperion Financial Management application interfaces. Because the vulnerability is accessible via SQL, a malicious actor with low-privileged credentials can craft and inject malicious SQL payloads designed to manipulate internal database queries executed by the Security component.\nThe step-by-step exploitation process begins with the attacker authenticating using low-privileged credentials. The attacker then transmits crafted database query strings targeting vulnerable entry points within the Security component. Because the application fails to properly parameterize or filter input data, the injected SQL commands are executed directly against the backend database with the execution privileges of the database user context used by Oracle Hyperion Financial Management.\nThrough this malicious database interaction, the attacker can bypass logical security boundaries, escalate privileges internally, and manipulate administrative records or session structures. Due to the scope change (S:C) characteristic of this vulnerability, the compromise of the security component and underlying database structures extends beyond the boundaries of Oracle Hyperion Financial Management, potentially granting unauthorized access to adjacent products and shared infrastructure.\nPost-exploitation impact includes full system takeover, unauthorized extraction of highly sensitive financial and operational data, corruption or destruction of critical system integrity parameters, and complete denial of service for dependent business operations."
}
CVE-2026-70920: Oracle Hyperion Financial Management Takeover Vulnerability (CRITICAL Severity, CVSS: 9.9) - Sceawere