Junglewise Threat Intelligence

CVE-2026-70911: Oracle Hyperion Financial Management authentication bypass

CVE-2026-70911 · Severity: medium · CVSS 5.3 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage budgets and financial data. An unauthenticated attacker can bypass security controls and read sensitive financial data without valid credentials, potentially exposing confidential information to unauthorized parties.

Technical details

The vulnerability is an authentication bypass in Oracle Hyperion Financial Management's security component affecting version 11.2.25.0.000. An unauthenticated attacker can exploit this via HTTP with no special preconditions (network access only), allowing unauthorized read access to a subset of accessible data. The attack requires no user interaction and has a CVSS 3.1 score of 5.3 (confidentiality impact only, no integrity or availability impact). Patches are available from Oracle.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats