Junglewise Threat Intelligence

CVE-2026-71146: Oracle Hyperion Financial Management partial denial of service in Security component

CVE-2026-71146 · Severity: low · CVSS 1.9 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation software used by large enterprises to manage budgets and close accounting processes. A vulnerability in its security component allows a high-privileged local attacker to cause a temporary disruption to the system's availability, affecting normal financial operations during an active attack.

Technical details

This is a local privilege-escalation denial-of-service vulnerability in the Security component of Oracle Hyperion Financial Management. The vulnerability requires a high-privileged attacker with logon access to the infrastructure where the product executes, and is classified as difficult to exploit (high complexity). Successful exploitation results in a partial denial of service with only availability impact; no data confidentiality or integrity compromise is possible. The vulnerability affects version 11.2.25.0.000 of Hyperion Financial Management and patches are expected from Oracle's August 2026 security update.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats