Junglewise Threat Intelligence

CVE-2026-70936: Oracle Hyperion Financial Management privilege escalation in security component

CVE-2026-70936 · Severity: high · CVSS 7.1 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and analysis platform used by enterprises to manage budgeting, forecasting, and reporting. A local privilege escalation vulnerability allows an attacker with limited user access to the server to gain unauthorized read, create, or delete access to sensitive financial data. Exploitation requires local logon to the infrastructure and could expose critical financial information or enable data tampering.

Technical details

This is a local privilege escalation vulnerability in the security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The vulnerability requires an attacker to have low-privilege logon access to the infrastructure where the product runs. The attack vector is local (AV:L) with low complexity (AC:L) and no user interaction required. Successful exploitation results in unauthorized access to confidentiality and integrity of critical data—allowing the attacker to read, create, modify, or delete financial data accessible by the application. No information is available on patch status from the accessible advisory text.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats