Sceawere

Vulnerability Detail

CVE-2026-70946UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Takeover

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management.
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-18T21:17:52.817Z",
  "pubdate": "2026-08-18T21:17:52.817Z",
  "executiveSummary": "A vulnerability has been identified within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. This security flaw is categorized as a difficult-to-exploit vulnerability that allows a low-privileged attacker with network access via HTTP to fully compromise the target system.\nSuccessful exploitation of this vulnerability results in the complete takeover of Oracle Hyperion Financial Management, leading to a total loss of confidentiality, integrity, and availability. According to the CVSS 3.1 scoring system, the vulnerability receives a base score of 7.5 with the vector string CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.\nThe attack vector is network-based, meaning the exploitation does not require physical access to the underlying infrastructure, but it does require high attack complexity and low-privileged authentication. Risk implications include unauthorized administrative access, data exfiltration, data manipulation, and service disruption across affected deployments.",
  "technicalDetails": "The vulnerability affects the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The root cause lies within the security controls and validation mechanisms handling network requests over the HTTP protocol.\nTo initiate an attack, a malicious actor must first obtain low-privileged credentials and establish network connectivity to the vulnerable Oracle Hyperion Financial Management application via HTTP. Although the vulnerability requires high attack complexity—indicating that successful exploitation demands specific race conditions, precise timing, or chaining of auxiliary flaws—a low-privileged attacker who overcomes these barriers can interact with the vulnerable Security component.\nThe attack flow proceeds as follows: The attacker crafts a specialized HTTP payload designed to bypass authorization boundaries enforced by the Security component. Because the component fails to properly validate or sanitize the incoming request under specific high-complexity execution states, the malicious payload is processed by the underlying application logic.\nUpon successful processing of the payload, the attacker elevates their privileges within the application context. This post-exploitation state grants the attacker full control over Oracle Hyperion Financial Management, resulting in complete system takeover. The impact compromises all security pillars: Confidentiality is violated through unauthorized access to sensitive financial data; Integrity is breached as unauthorized modifications can be made to financial records and application settings; and Availability is threatened due to the attacker's ability to disrupt or terminate service operations."
}
CVE-2026-70946: Oracle Hyperion Financial Management Takeover (HIGH Severity, CVSS: 7.5) - Sceawere