Junglewise Threat Intelligence

CVE-2026-71108: Oracle Hyperion Financial Management authorization bypass in Security component

CVE-2026-71108 · Severity: medium · CVSS 5.3 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage budgets and close operations. A vulnerability in the security component allows a low-privileged user with network access to gain unauthorized access to sensitive financial data, potentially exposing critical business information and reports to compromise.

Technical details

An authorization bypass vulnerability exists in the security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The flaw allows a low-privileged attacker with network access via HTTP to bypass access controls and retrieve sensitive financial data. The vulnerability is difficult to exploit and requires valid user credentials; however, successful exploitation results in unauthorized access to confidential financial information. No public exploit is known to be in active use, and Oracle has patched this issue as part of their August 2026 security updates.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: advisory

References

Related threats