Junglewise Threat Intelligence

CVE-2026-70934: Oracle Hyperion Financial Management privilege escalation in security component

CVE-2026-70934 · Severity: high · CVSS 7.1 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage critical financial data. A vulnerability in the security component allows low-privilege users with network access to gain unauthorized access to sensitive financial data and partially disrupt service availability. The exploit requires valid credentials but no complex interaction, making it a significant risk to organizations relying on this system.

Technical details

This is an authentication or authorization bypass vulnerability in Oracle Hyperion Financial Management 11.2.25.0.000, located in the security component. The vulnerability is easily exploitable via HTTP by a low-privileged, authenticated attacker with network access. No user interaction or complex configuration is required. A successful exploit can lead to unauthorized disclosure of all accessible financial data (high confidentiality impact) and a partial denial of service condition (low availability impact). Patch status and specific fix availability are not detailed in the advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed
  • other: Reported as CVE-2026-70934

References

Related threats