Junglewise Threat Intelligence

CVE-2026-70937: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-70937 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and management system used by enterprises to consolidate and analyze financial data. A vulnerability in the Security component allows a low-privileged authenticated attacker to gain full control over the system, potentially compromising all financial data and operations.

Technical details

This is a privilege escalation vulnerability in the Security component of Oracle Hyperion Financial Management. The vulnerability is difficult to exploit and requires network access via HTTP and low-level user privileges, but no user interaction is needed. A successful attack enables complete compromise of the system (confidentiality, integrity, and availability impacts). The attack vector is network-based with the precondition that the attacker has low-privileged authentication credentials. No patch information is available in the provided advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats