Junglewise Threat Intelligence

CVE-2026-70721: Oracle Hyperion Profitability and Cost Management authentication bypass in Deployment

CVE-2026-70721 · Severity: high · CVSS 8.6 · Published 2026-08-18

Technologies: Oracle Hyperion Profitability and Cost Management, Oracle Hyperion Profitability. Vendors: Oracle.

Executive brief

Oracle Hyperion Profitability and Cost Management is a financial planning and analysis tool used to manage organizational profitability and cost data. An unauthenticated attacker can bypass security controls over the network and access sensitive financial and cost management data without proper authorization, potentially exposing complete datasets and impacting related systems.

Technical details

This vulnerability is an authentication bypass or access control flaw in the Deployment component of Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000. The vulnerability is easily exploitable via HTTP from the network without requiring authentication, user interaction, or special privileges. An attacker can achieve unauthorized access to critical and sensitive data; the scope is marked as changed, indicating potential impact to additional systems beyond the primary vulnerable product. Oracle has released security updates as part of their August 2026 CPU advisory; patching to supported versions is the recommended mitigation.

Affected products

  • Oracle Hyperion Profitability and Cost Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats