Oracle has disclosed CVE-2026-61206, a critical vulnerability in the Security component of Oracle Hyperion Calculation Manager 11.2.25.0.000 that lets a low-privileged network attacker take over the product entirely.
What Is It
CVE-2026-61206 is a flaw in the Security component of Oracle Hyperion Calculation Manager, part of the Oracle Hyperion product family. Oracle describes it as an easily exploitable vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the product. Successful exploitation results in full takeover of Oracle Hyperion Calculation Manager.
The CVSS 3.1 base score is 9.9 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, low privileges required, no user interaction, and high impact to confidentiality, integrity, and availability.
Why It Matters
The scope is marked as changed (S:C). Oracle explicitly notes that while the vulnerability lives in Calculation Manager, attacks may significantly impact additional products. That is the difference between a single compromised application and a foothold that reaches beyond it, and it is what drives the score this high; the same vector with an unchanged scope (S:U) would rate 8.8.
The bar for the attacker is low: any account with minimal privileges and HTTP access to the service is sufficient. No user interaction is needed, and attack complexity is rated low. Hyperion deployments typically sit in financial planning and consolidation environments, so the data at risk is rarely trivial.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Hyperion Calculation Manager
- Component: Security
- Affected version: 11.2.25.0.000
No other versions or products are listed as affected in the supplied record.
Patch Status
The CVE was published on 2026-08-18 and is sourced from Oracle's security alert channel. Oracle ships Critical Patch Updates on a fixed quarterly schedule, January, April, July, and October, so there is no August release; the most recent CPU is July 2026, and the next is due in October 2026. Administrators running 11.2.25.0.000 should check the July 2026 CPU advisory for a listed fix and, if this CVE is not addressed there, plan for the October 2026 CPU as the delivery vehicle. Oracle's CPU advisory remains the authoritative reference for fixed versions and patch availability.
NVD status at time of writing is "Received," meaning the record has not yet completed NVD analysis and CPE enumeration is not published.
Sources
- NVD, CVE-2026-61206: https://nvd.nist.gov/vuln/detail/CVE-2026-61206
- Oracle Critical Patch Update Advisory, July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- Oracle Critical Patch Updates, Security Alerts and Bulletins: https://www.oracle.com/security-alerts/