Junglewise Threat Intelligence

CVE-2026-70909: Oracle Hyperion Financial Management unauthenticated access in security component

CVE-2026-70909 · Severity: high · CVSS 8.2 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and analysis platform used by enterprises to manage budgets, forecasts, and financial data. A vulnerability in the security component allows unauthenticated attackers on the network to gain unauthorized access to sensitive financial data and partially disrupt the service, without requiring any credentials or user interaction.

Technical details

An easily exploitable vulnerability exists in the security component of Oracle Hyperion Financial Management version 11.2.25.0.000, allowing unauthenticated network access via HTTP. The vulnerability permits attackers to bypass authentication controls and gain unauthorized access to critical financial data stored in the system, as well as trigger partial denial-of-service conditions. Attack requires only network reachability and no authentication or special preconditions. The vulnerability can result in complete data disclosure and partial service unavailability. Patch availability status is unknown at this time.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats