Sceawere

Vulnerability Detail

CVE-2026-71060UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Security Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.4
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.4",
  "pubDate": "2026-08-18T21:18:05.857Z",
  "pubdate": "2026-08-18T21:18:05.857Z",
  "executiveSummary": "A vulnerability has been identified within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. This security flaw is categorized as difficult to exploit, requiring specific attack conditions and high-privileged access.\nThe vulnerability allows an authenticated attacker with high privileges and network access via the HTTP protocol to compromise the confidentiality of the target application. Successful exploitation of this flaw can result in unauthorized access to critical data or complete access to all data accessible within Oracle Hyperion Financial Management.\nAccording to the CVSS 3.1 scoring system, the vulnerability has a base score of 4.4, with impacts strictly limited to confidentiality (C:H, I:N, A:N). The attack vector is network-based (AV:N), with high attack complexity (AC:H), requiring high privileges (PR:H), and no user interaction (UI:N) within an unchanged security scope (S:U).\nOrganizations utilizing the affected Oracle Hyperion Financial Management version must evaluate the risk, monitor for unauthorized administrative access, and apply official vendor patches or workarounds as soon as they become available to mitigate potential data exposure risks.",
  "technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management, specifically affecting version 11.2.25.0.000. The underlying root cause involves insufficient access controls or authorization validation mechanisms within the application's security architecture, which can be leveraged by a malicious actor possessing administrative or high-level privileges.\nExploitation of this vulnerability requires network access via the HTTP protocol. The attacker must already possess high-level privileges within the Oracle Hyperion Financial Management environment, indicating an insider threat scenario, a compromised administrative account, or chained vulnerabilities leading to privilege escalation.\nThe attack flow proceeds as follows: First, the adversary establishes network connectivity to the vulnerable Oracle Hyperion Financial Management HTTP interface. Second, the attacker authenticates using credentials that possess high privileges within the Security component. Third, leveraging the high-privileged access, the attacker crafts specific HTTP requests targeted at the flawed security component, bypassing intended authorization boundaries. Finally, the server processes the request and improperly discloses sensitive financial and operational data that the user should not normally be able to access based on granular privilege separation or least-privilege principles.\nThe post-exploitation impact is characterized by a complete compromise of data confidentiality. An attacker who successfully exploits this vulnerability can read, exfiltrate, or harvest critical corporate financial data, sensitive metadata, and all other datasets accessible to the Oracle Hyperion Financial Management instance, leading to severe regulatory, compliance, and business intelligence repercussions."
}
CVE-2026-71060: Oracle Hyperion Financial Management Security Vulnerability (MEDIUM Severity, CVSS: 4.4) - Sceawere