Junglewise Threat Intelligence

CVE-2026-70921: Oracle Hyperion Financial Management authentication bypass in TLS

CVE-2026-70921 · Severity: critical · CVSS 10 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage budgeting and accounting operations. A critical flaw allows unauthenticated attackers with network access to bypass security controls and gain full access to sensitive financial data, including the ability to read, create, modify, or delete records. This vulnerability poses an immediate risk to financial data integrity and compliance.

Technical details

This is an authentication bypass vulnerability in Oracle Hyperion Financial Management's TLS security component. The vulnerability is easily exploitable and requires no user interaction or special privileges; an attacker with network access can send specially crafted TLS traffic to compromise the system. The attack results in unauthorized access to critical financial data with both confidentiality (read access to all data) and integrity impacts (ability to create, modify, or delete records). The scope changes, meaning the vulnerability can affect other Oracle Hyperion products beyond Financial Management. Patches for version 11.2.25.0.000 are expected to be available through Oracle's security advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats