Junglewise Threat Intelligence

CVE-2026-71105: Oracle Hyperion Financial Management denial of service in Security component

CVE-2026-71105 · Severity: medium · CVSS 4.7 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage budgets and close books. A vulnerability in its security component allows a low-privileged attacker with local access to cause the application to hang or crash repeatedly, disrupting financial operations and user access to the system.

Technical details

This is a denial-of-service vulnerability in Oracle Hyperion Financial Management's Security component. The vulnerability is difficult to exploit and requires local access (adjacent network or physical presence on the infrastructure) combined with low-privileged logon credentials. The attack vector is local (AV:L) with high attack complexity (AC:H) and low privilege requirements (PR:L). Successful exploitation results in availability impact only—an attacker can cause the application to hang or repeatedly crash, but cannot leak data or modify information. No information on patch availability is provided in the advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats