Junglewise Threat Intelligence

CVE-2026-70735: Oracle Hyperion Profitability and Cost Management privilege escalation in Deployment

CVE-2026-70735 · Severity: high · CVSS 7.2 · Published 2026-08-18

Technologies: Oracle Hyperion Profitability and Cost Management, Oracle Hyperion Profitability. Vendors: Oracle.

Executive brief

Oracle Hyperion Profitability and Cost Management is an enterprise financial planning and analysis platform used to manage profitability models and cost allocations across organizations. A privilege escalation vulnerability in the Deployment component allows a high-privileged attacker with network access to take complete control of the system, potentially compromising sensitive financial data and operational continuity.

Technical details

This vulnerability in Oracle Hyperion Profitability and Cost Management (version 11.2.25.0.000) is exploitable via the Deployment component over HTTP without requiring complex exploitation techniques (low attack complexity). The vulnerability allows high-privileged attackers with network access to achieve remote compromise resulting in complete system takeover, affecting confidentiality, integrity, and availability. No user interaction is required for exploitation. Patch information is not available from the provided advisory summary; consult Oracle security advisories for available patches or workarounds.

Affected products

  • Oracle Hyperion Profitability and Cost Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats