Junglewise Threat Intelligence

CVE-2026-70736: Oracle Hyperion Profitability and Cost Management privilege escalation in Deployment

CVE-2026-70736 · Severity: high · CVSS 7.1 · Published 2026-08-18

Technologies: Oracle Hyperion Profitability and Cost Management, Oracle Hyperion Profitability. Vendors: Oracle.

Executive brief

Oracle Hyperion Profitability and Cost Management is a financial planning and analysis platform used by enterprises to track profitability metrics across business units. A privilege escalation vulnerability in the Deployment component allows an authenticated attacker with low-level access to read sensitive financial data and modify records without authorization, potentially compromising the integrity of financial reporting and analysis.

Technical details

This is an authorization bypass or privilege escalation vulnerability in the Deployment component of Oracle Hyperion Profitability and Cost Management (version 11.2.25.0.000). The vulnerability is easily exploitable and requires only network access via HTTP and a low-privileged user account (no admin access needed). An authenticated attacker can leverage this flaw to access confidential financial data across the entire system and perform unauthorized modifications (insert, update, or delete operations) to certain data records. The attack does not require user interaction and the fix/patch status is unknown based on available information.

Affected products

  • Oracle Hyperion Profitability and Cost Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats