Junglewise Threat Intelligence

CVE-2026-70938: Oracle Hyperion Financial Management unauthorized data access vulnerability in Security

CVE-2026-70938 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is an enterprise financial planning and consolidation system used to manage corporate accounting and reporting. A security vulnerability in the product allows a low-privileged network attacker to bypass access controls and read sensitive financial data, potentially exposing critical company information and regulatory filings.

Technical details

This is an access control or authentication bypass vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The vulnerability is easily exploitable and requires only low privilege credentials and network access via HTTP to trigger. An attacker with valid but limited user account access can escalate privileges or bypass authorization checks to access all data within the Hyperion Financial Management system. The vulnerability has high confidentiality impact but does not allow modification or deletion of data. Patch availability from Oracle is not explicitly confirmed in this advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats