Junglewise Threat Intelligence

CVE-2026-70723: Oracle Hyperion Profitability and Cost Management unauthorized data access in Deployment

CVE-2026-70723 · Severity: high · CVSS 7.7 · Published 2026-08-18

Technologies: Oracle Hyperion Profitability and Cost Management, Oracle Hyperion Profitability. Vendors: Oracle.

Executive brief

Oracle Hyperion Profitability and Cost Management is a financial planning and analysis tool used to manage profitability and cost data across enterprises. A vulnerability in the Deployment component allows a low-privileged network attacker with HTTP access to read sensitive financial data without authorization, potentially exposing confidential profitability metrics and cost information that could impact business decision-making and competitive positioning.

Technical details

The vulnerability exists in the Deployment component of Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000. It is an easily exploitable authentication or authorization bypass that allows a low-privileged attacker with network access via HTTP to gain unauthorized access to critical financial data. The attack requires valid low-level credentials but no user interaction. Successful exploitation results in high-impact confidentiality breach with access to all sensitive data within the application, and the scope impact indicates potential lateral movement affecting additional Oracle products in the environment. Patches are expected from Oracle's security advisory process.

Affected products

  • Oracle Hyperion Profitability and Cost Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats