{"cve":"CVE-2026-70723","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"11.2.25.0.000"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"Oracle Hyperion Profitability and Cost Management","source":"cna","vendor":"Oracle Corporation"},"product":"hyperion_profitability_and_cost_management","vendor":"oracle"}],"created":"2026-08-19T05:00:04.241628+00:00","title":"HTTP Access Enables Unauthorized Data Compromise in Oracle Hyperion Profitability and Cost Management","updated":"2026-08-21T09:30:09.024009+00:00","vendors":["oracle","oracle$PRODUCT$hyperion_profitability_and_cost_management"],"weaknesses":["CWE-284","CWE-200"]},"epss":{"score":0.00352},"mitre":{"cpes":["cpe:2.3:a:oracle:hyperion_profitability_and_cost_management:11.2.25.0.000:*:*:*:*:*:*:*"],"created":"2026-08-18T21:01:12.592000+00:00","description":"Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management.  While the vulnerability is in Oracle Hyperion Profitability and Cost Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.7,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/70xxx/CVE-2026-70723.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-25T15:11:22.740000+00:00","vendors":["oracle","oracle$PRODUCT$hyperion_profitability_and_cost_management"],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:oracle:hyperion_profitability_and_cost_management:11.2.25.0.000:*:*:*:*:*:*:*"],"created":"2026-08-18T21:17:24.790000+00:00","description":"Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management.  While the vulnerability is in Oracle Hyperion Profitability and Cost Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.7,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-70723.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-27T14:09:44.497000+00:00","vendors":["oracle","oracle$PRODUCT$hyperion_profitability_and_cost_management"],"weaknesses":["CWE-284"]},"opencve":{"changes":[{"created":"2026-08-18T21:15:00+00:00","data":[{"details":{"new":"Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management.  While the vulnerability is in Oracle Hyperion Profitability and Cost Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","old":null},"type":"description"},{"details":["oracle","oracle$PRODUCT$hyperion_profitability_and_cost_management"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:hyperion_profitability_and_cost_management:11.2.25.0.000:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle","oracle$PRODUCT$hyperion_profitability_and_cost_management"],"removed":[]},"type":"vendors"},{"details":{"added":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":7.7,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"d9d93553-46e3-4d51-be1a-e282150b52b3"},{"created":"2026-08-19T10:45:00+00:00","data":[{"details":{"new":"Unauthorized Data Disclosure via Low‑Privilege HTTP Access in Oracle Hyperion Profitability and Cost Management","old":null},"type":"title"},{"details":{"added":["CWE-285","CWE-522"],"removed":[]},"type":"weaknesses"}],"id":"c882f61c-8143-4e52-bf17-9f155e5a1c0d"},{"created":"2026-08-21T07:30:00+00:00","data":[{"details":{"new":null,"old":"Unauthorized Data Disclosure via Low‑Privilege HTTP Access in Oracle Hyperion Profitability and Cost Management"},"type":"title"},{"details":{"added":[],"removed":["CWE-285","CWE-522"]},"type":"weaknesses"}],"id":"7bc07d0d-e1f2-40aa-9a39-a03ec987c826"},{"created":"2026-08-21T09:45:00+00:00","data":[{"details":{"new":"HTTP Access Enables Unauthorized Data Compromise in Oracle Hyperion Profitability and Cost Management","old":null},"type":"title"},{"details":{"added":["CWE-200","CWE-284"],"removed":[]},"type":"weaknesses"}],"id":"7a24eb0a-2ff2-4fbe-8dd8-8150cd1939d5"},{"created":"2026-08-25T16:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"bf55bbd7-b5d0-4c59-b215-a64a06d0be23"}],"cpes":{"data":["cpe:2.3:a:oracle:hyperion_profitability_and_cost_management:11.2.25.0.000:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-08-18T21:01:12.592000+00:00","provider":"mitre"},"description":{"data":"Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management.  While the vulnerability is in Oracle Hyperion Profitability and Cost Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":7.7,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00352},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"providers":["mitre","nvd"]},"title":{"data":"HTTP Access Enables Unauthorized Data Compromise in Oracle Hyperion Profitability and Cost Management","provider":"enrichment"},"updated":{"data":"2026-08-25T16:17:25.080000+00:00","provider":"nvd"},"vendors":{"data":["oracle","oracle$PRODUCT$hyperion_profitability_and_cost_management"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-200","CWE-284"],"providers":["nvd","vulnrichment","enrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-08-18T21:01:12.592000+00:00","description":"Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management.  While the vulnerability is in Oracle Hyperion Profitability and Cost Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Profitability and Cost Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-08-25T15:00:35.302000+00:00","vendors":[],"vulnrichment_repo_path":"2026/70xxx/CVE-2026-70723.json","weaknesses":["CWE-284"]}}