Junglewise Threat Intelligence

CVE-2026-70848: Oracle Hyperion Financial Management unauthorized read access vulnerability

CVE-2026-70848 · Severity: low · CVSS 3.7 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage budgets and close processes. An unauthenticated attacker with network access can exploit a difficult-to-exploit security flaw to gain unauthorized read access to a subset of sensitive financial data in the system, potentially exposing confidential business information.

Technical details

This vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000 and allows unauthenticated, network-based attack via HTTP. The flaw is difficult to exploit and requires no user interaction. A successful attack results in limited unauthorized read access to a subset of accessible data within the application, impacting confidentiality only (no impact to integrity or availability). The attack vector is network-based (AV:N) with high attack complexity (AC:H), suggesting an exploitation barrier exists but can be overcome by a skilled attacker.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed
  • other: CVE-2026-70848

References

Related threats