Junglewise Threat Intelligence

CVE-2026-70928: Oracle Hyperion Financial Management SQL injection

CVE-2026-70928 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage accounting and reporting processes. A SQL injection vulnerability in the security component allows authenticated attackers with network access to gain complete control of the system, potentially compromising financial data, operational integrity, and system availability.

Technical details

The vulnerability is a SQL injection flaw in the security component of Oracle Hyperion Financial Management version 11.2.25.0.000. It requires low privileges and network access to exploit, with no user interaction needed. An authenticated attacker can inject malicious SQL commands to bypass security controls and achieve complete compromise of the application, including confidentiality, integrity, and availability impacts. The vulnerability has been assigned CVE-2026-70928 with a CVSS 3.1 score of 8.8.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats