{"cve":"CVE-2026-70754","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"11.2.25.0.000"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"Oracle Hyperion Financial Reporting","source":"cna","vendor":"Oracle Corporation"},"product":"hyperion_financial_reporting","vendor":"oracle"}],"created":"2026-08-19T02:00:05.010184+00:00","title":"Unauthenticated HTTP Access Enables Reading Sensitive Financial Data in Oracle Hyperion Financial Reporting","updated":"2026-08-21T08:00:08.306347+00:00","vendors":["oracle","oracle$PRODUCT$hyperion_financial_reporting"],"weaknesses":["CWE-284"]},"epss":{"score":0.00319},"mitre":{"cpes":["cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*"],"created":"2026-08-18T21:01:22.734000+00:00","description":"Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":5.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/70xxx/CVE-2026-70754.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-24T14:24:23.218000+00:00","vendors":["oracle","oracle$PRODUCT$hyperion_financial_reporting"],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*"],"created":"2026-08-18T21:17:28.230000+00:00","description":"Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":5.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-70754.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-24T15:44:28.020000+00:00","vendors":["oracle","oracle$PRODUCT$hyperion_financial_reporting"],"weaknesses":["CWE-284"]},"opencve":{"changes":[{"created":"2026-08-18T21:15:00+00:00","data":[{"details":{"new":"Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).","old":null},"type":"description"},{"details":["oracle","oracle$PRODUCT$hyperion_financial_reporting"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle","oracle$PRODUCT$hyperion_financial_reporting"],"removed":[]},"type":"vendors"},{"details":{"added":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":5.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"ccdf922d-8262-4d21-b120-49958cd07abf"},{"created":"2026-08-19T02:15:00+00:00","data":[{"details":{"new":"Unauthorized Data Access via HTTP in Oracle Hyperion Financial Reporting 11.2.25.0.000","old":null},"type":"title"},{"details":{"added":["CWE-284","CWE-285"],"removed":[]},"type":"weaknesses"}],"id":"6975cfed-ef11-4d74-8250-630470d00a46"},{"created":"2026-08-21T06:45:00+00:00","data":[{"details":{"new":null,"old":"Unauthorized Data Access via HTTP in Oracle Hyperion Financial Reporting 11.2.25.0.000"},"type":"title"},{"details":{"added":[],"removed":["CWE-284","CWE-285"]},"type":"weaknesses"}],"id":"fe2ea675-2f8c-48e8-b2a6-ca75fa4006bc"},{"created":"2026-08-21T08:15:00+00:00","data":[{"details":{"new":"Unauthenticated HTTP Access Enables Reading Sensitive Financial Data in Oracle Hyperion Financial Reporting","old":null},"type":"title"},{"details":{"added":["CWE-284"],"removed":[]},"type":"weaknesses"}],"id":"57f84e3c-5b34-4a75-b452-820f4dbcff1d"},{"created":"2026-08-24T15:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"1ef1d42e-bc86-4af0-bce2-f297440552f3"}],"cpes":{"data":["cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.25.0.000:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-08-18T21:01:22.734000+00:00","provider":"mitre"},"description":{"data":"Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":5.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00319},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"providers":["mitre","nvd"]},"title":{"data":"Unauthenticated HTTP Access Enables Reading Sensitive Financial Data in Oracle Hyperion Financial Reporting","provider":"enrichment"},"updated":{"data":"2026-08-24T15:16:39.670000+00:00","provider":"nvd"},"vendors":{"data":["oracle","oracle$PRODUCT$hyperion_financial_reporting"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-284"],"providers":["nvd","vulnrichment","enrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-08-18T21:01:22.734000+00:00","description":"Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-08-24T13:30:30.996000+00:00","vendors":[],"vulnrichment_repo_path":"2026/70xxx/CVE-2026-70754.json","weaknesses":["CWE-284"]}}