Sceawere

Vulnerability Detail

CVE-2026-71117UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Hyperion Financial Management Takeover Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management.
Vector String
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-18T21:18:12.350Z",
  "pubdate": "2026-08-18T21:18:12.350Z",
  "executiveSummary": "A difficult to exploit vulnerability exists within the Security component of the Oracle Hyperion Financial Management product, specifically affecting supported version 11.2.25.0.000. This vulnerability permits a highly privileged attacker who has achieved logon access to the underlying infrastructure where Oracle Hyperion Financial Management executes to compromise the application entirely. Successful exploitation of this security flaw can result in the complete takeover of Oracle Hyperion Financial Management.\nAlthough the vulnerable code resides strictly within Oracle Hyperion Financial Management, successful attack execution introduces a scope change, meaning that the fallout can significantly impact additional products sharing the infrastructure or trust boundary. The severity of this flaw is underscored by a CVSS 3.1 Base Score of 7.5, reflecting high impacts across Confidentiality, Integrity, and Availability. The attack vector requires local access, high privileges, and high complexity, alongside zero user interaction.",
  "technicalDetails": "The vulnerability manifests in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The underlying root cause involves insecure handling of security controls or execution parameters within the targeted infrastructure. Because the attack vector is local (AV:L), exploitation mandates that the adversary has already provisioned or acquired valid logon credentials and access to the host operating system or environment hosting the Oracle Hyperion Financial Management binaries and runtime execution context.\nThe exploitation prerequisites dictate high attack complexity (AC:H) and require high privileges (PR:H), implying that the threat actor must navigate stringent initial conditions, such as bypassing localized hardening controls, manipulating specific environment variables, or interacting with privileged administrative interfaces. No user interaction (UI:N) is required for successful execution, allowing an automated or direct local payload delivery once the prerequisites are met.\nThe attack flow proceeds as follows: First, the highly privileged local attacker establishes access to the infrastructure layer executing Oracle Hyperion Financial Management. Second, leveraging their elevated local standing and navigating the high complexity barriers, the actor interacts with the vulnerable Security component. Third, the attacker injects or executes unauthorized operational commands or malicious payloads designed to subvert the application logic. Because the scope changes (S:C), the compromise propagates beyond the immediate boundaries of Oracle Hyperion Financial Management, adversely affecting interconnected or co-located secondary products.\nPost-exploitation impact culminates in the complete takeover of Oracle Hyperion Financial Management. This grants the adversary unrestricted read, write, and execute capabilities over sensitive financial data, administrative configurations, and core application services, leading to severe breaches of confidentiality, data integrity destruction, and total service disruption across impacted systems."
}
CVE-2026-71117: Oracle Hyperion Financial Management Takeover Vulnerability (HIGH Severity, CVSS: 7.5) - Sceawere