Vulnerability in Oracle Hyperion Financial Management Product by Oracle
CVE-2026-70847

6.5MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70847?

This vulnerability in the Oracle Hyperion Financial Management component allows low-privileged attackers with access to the infrastructure to compromise the system. Even though the vulnerability is specific to Oracle Hyperion Financial Management, successful exploitation can have broader implications, potentially affecting additional products within the ecosystem. Attackers could gain unauthorized access to sensitive data or complete control over all accessible data, leading to significant data security risks.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.25.0.000

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.