Unauthorized Data Access in Oracle Hyperion Financial Management
CVE-2026-70843

6.8MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70843?

A vulnerability in Oracle Hyperion Financial Management allows an unauthenticated attacker, with physical access to the communication segment, to compromise the system. This flaw enables unauthorized creation, deletion, or modification of sensitive data, providing the potential for complete access to critical data within Oracle Hyperion Financial Management. Proper security measures should be implemented to mitigate the risk and protect unauthorized access to sensitive information.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.25.0.000

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.