Sceawere
Vulnerability Detail
CVE-2026-71060UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Security Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.4
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.4",
"pubDate": "2026-08-18T21:18:05.857Z",
"pubdate": "2026-08-18T21:18:05.857Z",
"executiveSummary": "A vulnerability has been identified within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. This security flaw is categorized as difficult to exploit, requiring specific attack conditions and high-privileged access.\nThe vulnerability allows an authenticated attacker with high privileges and network access via the HTTP protocol to compromise the confidentiality of the target application. Successful exploitation of this flaw can result in unauthorized access to critical data or complete access to all data accessible within Oracle Hyperion Financial Management.\nAccording to the CVSS 3.1 scoring system, the vulnerability has a base score of 4.4, with impacts strictly limited to confidentiality (C:H, I:N, A:N). The attack vector is network-based (AV:N), with high attack complexity (AC:H), requiring high privileges (PR:H), and no user interaction (UI:N) within an unchanged security scope (S:U).\nOrganizations utilizing the affected Oracle Hyperion Financial Management version must evaluate the risk, monitor for unauthorized administrative access, and apply official vendor patches or workarounds as soon as they become available to mitigate potential data exposure risks.",
"technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management, specifically affecting version 11.2.25.0.000. The underlying root cause involves insufficient access controls or authorization validation mechanisms within the application's security architecture, which can be leveraged by a malicious actor possessing administrative or high-level privileges.\nExploitation of this vulnerability requires network access via the HTTP protocol. The attacker must already possess high-level privileges within the Oracle Hyperion Financial Management environment, indicating an insider threat scenario, a compromised administrative account, or chained vulnerabilities leading to privilege escalation.\nThe attack flow proceeds as follows: First, the adversary establishes network connectivity to the vulnerable Oracle Hyperion Financial Management HTTP interface. Second, the attacker authenticates using credentials that possess high privileges within the Security component. Third, leveraging the high-privileged access, the attacker crafts specific HTTP requests targeted at the flawed security component, bypassing intended authorization boundaries. Finally, the server processes the request and improperly discloses sensitive financial and operational data that the user should not normally be able to access based on granular privilege separation or least-privilege principles.\nThe post-exploitation impact is characterized by a complete compromise of data confidentiality. An attacker who successfully exploits this vulnerability can read, exfiltrate, or harvest critical corporate financial data, sensitive metadata, and all other datasets accessible to the Oracle Hyperion Financial Management instance, leading to severe regulatory, compliance, and business intelligence repercussions."
}