Sceawere
Vulnerability Detail
CVE-2026-71150UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Hyperion Financial Management Takeover
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-18T21:18:16.057Z",
"pubdate": "2026-08-18T21:18:16.057Z",
"executiveSummary": "A critical security vulnerability has been identified within the Oracle Hyperion Financial Management product, specifically affecting the Security component in version 11.2.25.0.000. This vulnerability allows an authenticated attacker with low privileges and network access via the HTTP protocol to execute a full system compromise. Successful exploitation of this flaw grants the adversary complete takeover capabilities over the targeted Oracle Hyperion Financial Management instance, resulting in severe impacts across all three pillars of the CIA triad: confidentiality, integrity, and availability. The CVSS 3.1 base score is calculated at 8.8, reflecting the high severity of the risk. The attack vector is strictly network-based, featuring low attack complexity and requiring no user interaction, though it does necessitate low-privilege authentication. Risk implications include unauthorized data access, malicious modification of critical financial data, and complete denial of service. Remediation requires strict adherence to vendor-supplied patches and security advisories.",
"technicalDetails": "The vulnerability resides in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The root cause stems from improper input validation, authorization enforcement, or access control mechanisms within the application logic handled by the affected component. Because the vulnerability is exposed via the HTTP protocol over the network, an attacker possessing valid low-privileged credentials can interact directly with vulnerable endpoints exposed by the web application server.\nThe attack flow begins with the threat actor authenticating to the network interface of the Oracle Hyperion Financial Management application using low-privileged credentials. Once authenticated, the attacker crafts a malicious HTTP request targeting the vulnerable Security component. Due to insufficient validation or flawed access controls, the application processes the malicious payload, allowing the attacker to bypass intended authorization boundaries. This enables the execution of unauthorized administrative functions or arbitrary operations within the context of the application.\nPost-exploitation impact is catastrophic, resulting in a total takeover of the Oracle Hyperion Financial Management environment. An attacker achieving this level of compromise gains full control over sensitive financial records and system configurations, fulfilling high impacts for confidentiality, integrity, and availability as designated by the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerability requires low attack complexity (AC:L), meaning successful exploitation is reliably repeatable by attackers with minimal technical hurdles once initial low-privileged access is established."
}