Junglewise Threat Intelligence

CVE-2026-70714: Oracle Hyperion Calculation Manager integrity bypass in security component

CVE-2026-70714 · Severity: medium · CVSS 4.1 · Published 2026-08-18

Technologies: Oracle Hyperion Calculation Manager. Vendors: Oracle.

Executive brief

Oracle Hyperion Calculation Manager is a financial planning and analysis tool used to manage complex calculations across enterprise systems. A local vulnerability allows an attacker with administrative access and logon capability to modify or delete critical financial data without authorization, potentially compromising data integrity across the organization's planning and reporting processes.

Technical details

This is an integrity-based vulnerability in the security component of Oracle Hyperion Calculation Manager version 11.2.25.0.000. The vulnerability requires local access (AV:L) and high privileges (PR:H), with a high complexity bar (AC:H) making it difficult to exploit. An authenticated high-privileged attacker with logon access to the infrastructure can bypass security controls to create, delete, or modify critical data within the application. No patch status is indicated in the advisory; users should consult Oracle's security updates for remediation.

Affected products

  • Oracle Hyperion Calculation Manager 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats