Junglewise Threat Intelligence

CVE-2026-70919: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-70919 · Severity: low · CVSS 2.5 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial consolidation and reporting system used by enterprises to manage and analyze financial data. A vulnerability in the product's security component allows an authenticated local attacker to modify financial data (insert, update, or delete records) without proper authorization, requiring user interaction to exploit. This could lead to unauthorized changes to financial records and potential compliance violations.

Technical details

The vulnerability is a privilege escalation flaw in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. It requires local access to the infrastructure where the product executes (AV:L), a high complexity attack (AC:H), no special privileges (PR:N), and user interaction (UI:R) to exploit. An unauthenticated attacker with local logon access can achieve unauthorized update, insert, or delete access to Oracle Hyperion Financial Management data. The vulnerability does not provide confidentiality or availability impacts, only integrity impacts. No patch information is currently available in the advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed: Published in Oracle Security Alert

References

Related threats