Junglewise Threat Intelligence

CVE-2026-70916: Oracle Hyperion Financial Management local privilege escalation

CVE-2026-70916 · Severity: medium · CVSS 4 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation tool used by large enterprises. A vulnerability in the security component allows an attacker with local access to the server to read sensitive financial data without proper authentication, potentially exposing confidential business information and regulatory reports.

Technical details

The vulnerability is a local privilege escalation issue in the security component of Oracle Hyperion Financial Management version 11.2.25.0.000. It requires an unauthenticated attacker with local logon access to the infrastructure where the product executes. Successful exploitation results in unauthorized read access to a subset of application data. The attack vector is local with no special privileges or user interaction required. The CVSS 3.1 vector is (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N), indicating low complexity local exploitation with confidentiality impact only.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats