Sceawere

Vulnerability Detail

CVE-2026-70929UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Security Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-18T21:17:50.863Z",
  "pubdate": "2026-08-18T21:17:50.863Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Security component of the Oracle Hyperion Financial Management product, specifically affecting version 11.2.25.0.000. This security flaw allows a low-privileged remote attacker with network access via the HTTP protocol to compromise the affected system, leading to severe unauthorized data manipulation and disclosure risks.\nSuccessful exploitation of this vulnerability grants the attacker unauthorized creation, deletion, or modification capabilities over critical data and all accessible information within Oracle Hyperion Financial Management. Additionally, it provides unauthorized read access to critical and complete data sets managed by the application. The severity of this issue is reflected in a CVSS 3.1 Base Score of 8.1, with high impacts to both confidentiality and integrity, while availability remains unaffected.\nThe attack vector is network-based (AV:N), requiring low attack complexity (AC:L) and low privileges (PR:L), with no user interaction (UI:N) required. The scope remains unchanged (S:U). Organizations utilizing the affected version face significant risk of data compromise and integrity violation, necessitating immediate review and application of vendor-supplied remediation guidance.",
  "technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The application fails to properly enforce authorization checks and access control boundaries during request processing over the HTTP protocol, allowing authenticated users with low privileges to transcend their assigned roles and execute unauthorized administrative or data-access operations.\nExploitation requires the attacker to possess network connectivity to the vulnerable Oracle Hyperion Financial Management instance via HTTP. Because the attack complexity is low and user interaction is not required, an attacker with valid low-privileged credentials can craft malicious HTTP requests directed at the vulnerable Security component endpoints. These requests bypass standard validation checks due to inadequate server-side authorization enforcement.\nDuring the attack flow, the malicious HTTP payload interacts directly with the vulnerable backend logic of the Security component. The system processes the request under the assumption that proper access validation has occurred, whereas the lack of strict authorization controls permits the low-privileged actor to perform privileged operations.\nThe post-exploitation impact includes unauthorized data manipulation, where the attacker can create, modify, or delete critical enterprise financial data and any other accessible information within the Oracle Hyperion Financial Management ecosystem. Furthermore, the attacker gains complete unauthorized access to view confidential data, violating core confidentiality and integrity principles without causing a denial of service to system availability."
}
CVE-2026-70929: Oracle Hyperion Financial Management Security Vulnerability (HIGH Severity, CVSS: 8.1) - Sceawere