Junglewise Threat Intelligence

CVE-2026-70935: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-70935 · Severity: high · CVSS 7.1 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation application used by organizations to manage critical accounting data and reporting. A vulnerability in its security component allows a low-privileged user with network access to view unauthorized financial data and temporarily disrupt the system, potentially exposing sensitive accounting information and affecting business operations.

Technical details

This is a privilege escalation vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The vulnerability is network-exploitable via HTTP and requires low privilege credentials and no user interaction. An attacker with low privileges can leverage the flaw to gain unauthorized access to sensitive financial data (high confidentiality impact) and cause partial denial of service (low availability impact). The exact root cause and patch status are not detailed in the advisory; Oracle's security bulletin should be consulted for remediation guidance.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats