Junglewise Threat Intelligence

CVE-2026-71119: Oracle Hyperion Financial Management local privilege escalation in Security component

CVE-2026-71119 · Severity: medium · CVSS 6.4 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and analysis platform used by enterprises to manage budgets and consolidate financial data. This vulnerability allows a privileged user with local access to the system to gain complete control over the application, potentially compromising financial data and operations. The attack is difficult to execute and requires high-level privileges and direct access to the infrastructure.

Technical details

This is a local privilege escalation vulnerability in the Security component of Oracle Hyperion Financial Management 11.2.25.0.000. The vulnerability requires an attacker with high privileges and logon access to the infrastructure where the application runs, combined with difficult-to-meet conditions (AC:H). Successful exploitation results in full compromise of the Oracle Hyperion Financial Management instance, allowing takeover of the application with impact to confidentiality, integrity, and availability of financial data. The CVSS 3.1 vector (AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H) reflects the local attack vector and high privilege requirements, with a base score of 6.4.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats