Sceawere

Vulnerability Detail

CVE-2026-70936UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Privilege Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-18T21:17:51.663Z",
  "pubdate": "2026-08-18T21:17:51.663Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Security component of the Oracle Hyperion Financial Management product, specifically affecting version 11.2.25.0.000.\nThe vulnerability allows a low-privileged attacker who has obtained local logon access to the underlying infrastructure where Oracle Hyperion Financial Management executes to compromise the application.\nSuccessful exploitation of this flaw can result in unauthorized creation, deletion, or modification access to critical data and all accessible Oracle Hyperion Financial Management data.\nAdditionally, successful attacks can lead to unauthorized or complete access to all sensitive and critical data managed by the system.\nThe CVSS 3.1 Base Score is 7.1, with high impacts on both confidentiality and integrity, while availability remains unaffected.\nThe attack vector is local, requiring low privileges and no user interaction, demonstrating significant risk for environments with insufficient host-level segregation or hardening.",
  "technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000, which fails to adequately enforce authorization or access control boundaries for authenticated local users.\nAttack execution requires the threat actor to already possess low-privileged logon access to the host infrastructure hosting the Oracle Hyperion Financial Management execution environment.\nDue to improper access controls or insecure handling of privileged security functions within the vulnerable component, a low-privileged user can leverage local execution capabilities to bypass intended security restrictions.\nThe attack flow involves the local user interacting with the vulnerable Security component routines, escalating their operational capabilities beyond their assigned authorization level.\nOnce the security boundary is bypassed, the attacker gains unauthorized administrative or elevated data access capabilities.\nPost-exploitation impact includes the ability to execute unauthorized data manipulation operations, such as creating, modifying, or deleting critical application data, as well as exfiltrating sensitive financial and operational records.\nThe network exposure is classified as local (AV:L), meaning remote network access is not required to initiate the attack vector, but host-level access is a prerequisite.\nThe complexity of the exploit is low (AC:L), and user interaction is not required (UI:N), allowing an attacker to reliably compromise the confidentiality and integrity (C:H/I:H) of the target application data."
}
CVE-2026-70936: Oracle Hyperion Financial Management Privilege Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere