Sceawere
Vulnerability Detail
CVE-2026-70952UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Security Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-08-18T21:17:53.493Z",
"pubdate": "2026-08-18T21:17:53.493Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Security component of the Oracle Hyperion Financial Management product. The affected supported version is 11.2.25.0.000. This security flaw allows an unauthenticated remote attacker with network access via the HTTP protocol to compromise the target application. Successful exploitation of this vulnerability leads to severe confidentiality and availability impacts, granting unauthorized access to critical or complete data accessible by Oracle Hyperion Financial Management, alongside an unauthorized ability to induce a partial denial of service condition. The vulnerability carries a CVSS 3.1 Base Score of 8.2, reflecting high risk due to the lack of required authentication, privileges, or user interaction for successful execution over a network attack vector.",
"technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The root cause stems from improper input validation or insufficient access control enforcement within the network-exposed HTTP interface handling security-related operations. Because the attack vector is network-based (AV:N) and requires low attack complexity (AC:L), an adversary can interact directly with the vulnerable HTTP service without possessing any prior authentication credentials (PR:N) or requiring user interaction (UI:N).\nThe attack flow proceeds as follows: an unauthenticated threat actor constructs a maliciously crafted HTTP request targeting the exposed Security component of Oracle Hyperion Financial Management. Upon receipt of this request, the vulnerable component fails to properly validate the input or enforce authorization checks before processing the payload. This flaw permits the execution of unauthorized functional paths or data queries.\nThe resulting post-exploitation impact encompasses two primary vectors defined by the CVSS 3.1 vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L): first, it yields high confidentiality (C:H) compromise, allowing the attacker to read critical, sensitive financial and operational data stored or processed by the application; second, it causes a partial availability (A:L) impact, enabling the adversary to disrupt service operations and induce a partial denial of service condition against the Oracle Hyperion Financial Management environment."
}