Junglewise Threat Intelligence

CVE-2026-71103: Oracle Hyperion Financial Management authentication bypass in security component

CVE-2026-71103 · Severity: medium · CVSS 6.3 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and reporting system used by enterprises to manage budgeting, consolidation, and performance management. A vulnerability in its security component allows a low-privileged user with network access to read, modify, or delete sensitive financial data and cause service disruptions, potentially exposing confidential financial information and compromising data integrity.

Technical details

The vulnerability is an authentication or authorization bypass in the security component of Oracle Hyperion Financial Management version 11.2.25.0.000. It is easily exploitable over HTTP by an attacker with low-level network access and does not require user interaction. The flaw allows unauthorized read access to a subset of accessible data, unauthorized update/insert/delete operations on data, and the ability to cause partial denial of service. No patch status is currently documented in the advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats