Sceawere
Vulnerability Detail
CVE-2026-71013UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Privilege Compromise
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.0",
"pubDate": "2026-08-18T21:18:00.653Z",
"pubdate": "2026-08-18T21:18:00.653Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Security component of the Oracle Hyperion Financial Management product, specifically affecting version 11.2.25.0.000.\nThis vulnerability allows an attacker with high privileges and local logon access to the underlying infrastructure where Oracle Hyperion Financial Management executes to successfully compromise the application.\nSuccessful exploitation of this flaw can result in unauthorized creation, deletion, and modification access to critical data, as well as complete unauthorized access to all accessible application data, impacting both confidentiality and integrity.\nThe risk implications are significant for organizations utilizing the affected version, as a compromised financial management system can lead to severe data integrity breaches of sensitive corporate financial information.\nAccording to the CVSS 3.1 metrics, the vulnerability carries a base score of 6.0 with the vector (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).\nExploitation requires physical or remote interactive logon access to the host infrastructure, coupled with high privileges, but does not require user interaction and is assessed with low attack complexity.",
"technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000.\nThe attack vector is local (AV:L), meaning the adversary must already possess authorized logon access to the host operating system or infrastructure where the target software service executes.\nThe attack complexity is low (AC:L), indicating that once the prerequisite access and privileges are met, the exploitation steps do not require specialized or complex conditions to succeed.\nAuthentication and privilege requirements dictate that the attacker must operate with high privileges (PR:H) within the environment, leveraging administrative or elevated system access to interact with the vulnerable component.\nUser interaction is not required (UI:N), allowing the attack to proceed deterministically without social engineering or manual intervention from other users.\nThe scope is unchanged (S:U), as the security impact is restricted to the vulnerable Oracle Hyperion Financial Management authorization boundary rather than bleeding into completely unrelated host kernel domains.\nThe step-by-step attack flow begins with the high-privileged adversary establishing a session on the infrastructure hosting the Oracle Hyperion Financial Management execution environment. Leveraging their elevated privileges, the attacker interacts directly with the Security component. Due to insufficient access controls or insecure handling within this component, the attacker bypasses intended authorization boundaries. This allows them to manipulate, inject, or extract sensitive internal security structures and operational data.\nPost-exploitation impacts materialize as a complete compromise of confidentiality (C:H) and integrity (I:H) concerning the application data. The attacker gains the capability to execute unauthorized create, delete, or modify operations on critical data stores, alongside unauthorized readout access to all accessible Oracle Hyperion Financial Management data assets. Availability remains unaffected (A:N), as the attack vectors focus on data compromise rather than denial of service."
}