Junglewise Threat Intelligence

CVE-2026-70733: Oracle Hyperion Profitability and Cost Management authorization bypass in Deployment

CVE-2026-70733 · Severity: high · CVSS 7.1 · Published 2026-08-18

Technologies: Oracle Hyperion Profitability and Cost Management, Oracle Hyperion Profitability. Vendors: Oracle.

Executive brief

Oracle Hyperion Profitability and Cost Management is a financial planning and analysis solution used to model and analyze business costs and profitability. A network-accessible vulnerability in the Deployment component allows low-privileged users to gain unauthorized access to sensitive financial data and cause partial service disruption, potentially exposing confidential business intelligence and impacting operational availability.

Technical details

A network-exploitable authorization vulnerability exists in Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000, accessible via HTTP with low privilege credentials and no user interaction required. The vulnerability allows an authenticated attacker to bypass access controls in the Deployment component, resulting in unauthorized read access to protected data and the ability to trigger partial denial of service conditions. The CVSS 3.1 score of 7.1 reflects high confidentiality and limited availability impact. Patches should be available through Oracle's Critical Patch Update program.

Affected products

  • Oracle Hyperion Profitability and Cost Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats