Sceawere
Vulnerability Detail
CVE-2026-70943UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Compromise
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-08-18T21:17:52.463Z",
"pubdate": "2026-08-18T21:17:52.463Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Security component of the Oracle Hyperion Financial Management product, specifically affecting version 11.2.25.0.000. This security flaw enables an unauthenticated attacker to compromise the target application, leading to severe unauthorized data manipulation and exposure risks. The vulnerability presents a significant risk to organizational data governance, as successful exploitation yields severe impacts on both data confidentiality and integrity.\nThe attacker capabilities required to leverage this vulnerability include unauthenticated access coupled with network positioning on the physical communication segment directly attached to the underlying hardware where the Oracle Hyperion Financial Management instance executes. While exploitation requires localized physical segment access rather than wide-area network reachability, the attack complexity remains low, requiring no user interaction or prior privileges.\nSuccessful exploitation results in unauthorized creation, deletion, or modification capabilities affecting critical data and all accessible information within Oracle Hyperion Financial Management. Furthermore, attackers gain unauthorized access to critical data or complete access to all data accessible by the application, directly violating foundational security principles.",
"technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. Based on the CVSS 3.1 vector (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), the attack vector is categorized as adjacent (AV:A), meaning the attacker must have access to the physical communication segment attached to the hardware hosting the vulnerable software. The attack complexity is low (AC:L), indicating that the exploitation mechanism does not require sophisticated conditions or complex cryptographic bypasses.\nAuthentication requirements are nonexistent (PR:N), and zero user interaction (UI:N) is mandated for a successful attack payload to execute. The scope remains unchanged (S:U), but the impact metrics register high severity for both confidentiality (C:H) and integrity (I:H), while availability is unaffected (A:N).\nThe attack flow proceeds as follows: First, an unauthenticated attacker establishes a presence on the physical communication segment connected to the hardware executing Oracle Hyperion Financial Management. Second, leveraging the low complexity conditions of the security flaw, the attacker transmits crafted network payloads targeting the vulnerable Security component without requiring valid credentials or session tokens. Third, the targeted component processes the input insecurely, failing to properly validate authorization boundaries or message integrity on the local communication segment. Finally, the attacker achieves complete compromise of the application's security context, allowing unauthorized read, write, and delete operations against critical application data stores and sensitive financial records."
}