Junglewise Threat Intelligence

CVE-2026-70943: Oracle Hyperion Financial Management privilege escalation via physical access

CVE-2026-70943 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is financial planning and analysis software used by enterprises to manage budgets, forecasts, and accounting data. An attacker with physical access to the network infrastructure can compromise the system without authentication, gaining the ability to read, modify, or delete sensitive financial data and records.

Technical details

This is a privilege escalation vulnerability in the security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The vulnerability requires physical access to the network segment where the Hyperion Financial Management system operates, but no authentication credentials or user interaction. An unauthenticated attacker can exploit this flaw to gain unauthorized access to critical financial data, including creation, modification, and deletion of records, as well as complete read access to all data accessible to the system. The vulnerability affects confidentiality and integrity of the system's data. Patches are expected from Oracle as part of their August 2026 security updates.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats