Junglewise Threat Intelligence

CVE-2026-71109: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-71109 · Severity: medium · CVSS 6.7 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation system used by large enterprises to manage accounting and reporting operations. A privilege escalation vulnerability in the Security component allows a high-privileged local attacker to fully compromise the system, potentially exposing or manipulating financial data and disrupting critical business operations.

Technical details

The vulnerability is a privilege escalation flaw in the Security component of Oracle Hyperion Financial Management affecting version 11.2.25.0.000. It requires high privileges and local access (logon to the infrastructure where the product executes), but no user interaction is needed. Successful exploitation allows a high-privileged attacker to achieve complete system compromise, impacting confidentiality, integrity, and availability. A patch is presumed to be available through Oracle's security updates, though the advisory page is not fully accessible in the reference materials.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats