Junglewise Threat Intelligence

CVE-2026-70929: Oracle Hyperion Financial Management privilege escalation in security component

CVE-2026-70929 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is an enterprise financial planning and consolidation system used by organizations to manage budgeting, forecasting, and financial consolidation processes. A low-privilege attacker with network access can exploit a security flaw to gain unauthorized access to, modify, or delete critical financial data. This could enable unauthorized changes to financial records, data exfiltration, or destruction of financial information.

Technical details

This is a privilege escalation vulnerability in Oracle Hyperion Financial Management's security component, affecting version 11.2.25.0.000. The vulnerability is easily exploitable via network access (HTTP) and requires only low-privilege authentication; no user interaction is needed. A successful attack allows an attacker to create, delete, or modify critical financial data, or gain complete unauthorized read access to all accessible financial management data. The vulnerability impacts both confidentiality and integrity of the system. A patch is expected to be available through Oracle's standard security update process.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: advisory

References

Related threats