Junglewise Threat Intelligence

CVE-2026-70711: Oracle Hyperion Calculation Manager privilege escalation in Security component

CVE-2026-70711 · Severity: low · CVSS 3.6 · Published 2026-08-18

Technologies: Oracle Hyperion Calculation Manager. Vendors: Oracle.

Executive brief

Oracle Hyperion Calculation Manager is a financial planning and forecasting system used by enterprises. A vulnerability in its security component allows a local attacker with infrastructure access to gain unauthorized read and modify access to sensitive financial data, though successful exploitation requires social engineering of another user.

Technical details

The vulnerability is a privilege escalation issue in the Security component of Oracle Hyperion Calculation Manager version 11.2.25.0.000. It requires local infrastructure access (attack vector is local), has high complexity, and necessitates user interaction from someone other than the attacker to be successfully exploited. A successful attack can result in unauthorized data modification (insert, update, delete) and unauthorized read access to a subset of the application's data. No information on patch availability is available from the provided advisory text.

Affected products

  • Oracle Hyperion Calculation Manager 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats