Sceawere
Vulnerability Detail
CVE-2026-71144UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Security Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data.
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 3.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.0",
"pubDate": "2026-08-18T21:18:15.367Z",
"pubdate": "2026-08-18T21:18:15.367Z",
"executiveSummary": "A security vulnerability has been identified in the Security component of Oracle Hyperion Financial Management, specifically affecting version 11.2.25.0.000. This vulnerability is classified as difficult to exploit and requires an attacker to possess high privileges along with interactive logon access to the underlying infrastructure where Oracle Hyperion Financial Management executes. Successful exploitation of this flaw can compromise the integrity and confidentiality of the application, resulting in unauthorized read, update, insert, or delete access to a subset of data accessible by Oracle Hyperion Financial Management. The vulnerability carries a CVSS 3.1 Base Score of 3.0 with a vector of CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N, indicating that availability is not impacted and that network attack vectors are absent. The risk implications primarily involve insider threats or compromised administrative accounts capable of leveraging local infrastructure access to manipulate sensitive financial data residing within the application domain. Organizations utilizing the affected version must review administrative access controls and apply appropriate hardening measures to mitigate potential privilege abuse vectors.",
"technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The root cause stems from insufficient access controls or improper handling of authorization boundaries within the application's local execution environment, allowing highly privileged users to bypass intended security constraints. Because the attack vector is local (AV:L), remote network exploitation is precluded, necessitating that the adversary already has established logon access to the host infrastructure hosting the Oracle Hyperion Financial Management service. Furthermore, the attack complexity is rated as high (AC:H), meaning that successful exploitation requires specific race conditions, complex configurations, or precise timing conditions to be met by the threat actor. Privilege requirements are set to high (PR:H), mandating that the attacker operates with elevated administrative privileges within the local operating system or infrastructure layer prior to initiating the attack sequence. User interaction is not required (UI:N). The attack flow typically begins with the high-privileged attacker establishing an interactive logon session on the target infrastructure. Leveraging their administrative standing, the attacker interacts with local execution components or exposed interfaces of the vulnerable Security component. Due to the flaw in privilege enforcement or data handling, the attacker can execute unauthorized operations against the application data store. The post-exploitation impact includes unauthorized read access to a subset of sensitive financial data as well as unauthorized update, insert, or delete capabilities against accessible records, thereby compromising data integrity and confidentiality without causing a denial of service (A:N)."
}