Junglewise Threat Intelligence

CVE-2026-70850: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-70850 · Severity: low · CVSS 3 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is an enterprise financial consolidation and planning platform used by large organizations to manage accounting data and reporting. A flaw in its security component allows a highly privileged attacker with local access to modify or delete financial data and temporarily disrupt service. This could compromise the integrity of critical financial records and cause brief operational disruption.

Technical details

This is a privilege-related vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The vulnerability requires local access to the infrastructure where the product runs and high-level privileges to exploit, making it difficult to weaponize remotely. Successful exploitation allows an attacker to perform unauthorized data modification, insertion, or deletion on accessible financial data and cause a partial denial of service. The attack vector is local with high attack complexity and requires high privileges; no code execution is achieved. A patch is expected through Oracle's regular security update cycle.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats