Vulnerability in Oracle Hyperion Financial Management Security Component
CVE-2026-70842

8.4HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70842?

A security vulnerability in Oracle Hyperion Financial Management enables low-privileged attackers with access to the infrastructure to compromise the system. This can lead to unauthorized creation, deletion, or modification of critical data, potentially affecting not only the Hyperion Financial Management product but also other related systems. The vulnerability poses risks to data confidentiality and integrity, allowing extensive unauthorized access to sensitive information.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.25.0.000

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.