Junglewise Threat Intelligence

CVE-2026-71147: Oracle Hyperion Financial Management input validation vulnerability

CVE-2026-71147 · Severity: medium · CVSS 4.2 · Published 2026-08-18

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage budgets and close operations. An unauthenticated attacker can exploit this vulnerability via HTTP if they trick a user into clicking a malicious link, potentially modifying or deleting financial data or causing temporary service disruption. The attack is difficult to carry out but does not require the attacker to be authenticated to the system.

Technical details

This is a network-accessible vulnerability in Oracle Hyperion Financial Management's security component that can be exploited without authentication via HTTP. The vulnerability is difficult to exploit and requires user interaction (tricking a user to click a link or perform an action), suggesting it may involve client-side attacks such as cross-site request forgery (CSRF) or cross-site scripting (XSS). Successful exploitation can result in unauthorized modification, insertion, or deletion of financial data and partial denial of service. The vulnerability affects version 11.2.25.0.000 and patches are expected from Oracle's security advisory.

Affected products

  • Oracle Hyperion Financial Management 11.2.25.0.000

Timeline

  • 2026-08-18: disclosed

References

Related threats