Vulnerability in Oracle Hyperion Financial Management Security Component
CVE-2026-70850

3LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70850?

A security vulnerability has been identified in Oracle Hyperion Financial Management, specifically in the Security component. This issue affects version 11.2.25.0.000 and allows a high-privileged attacker, with access to the infrastructure where Oracle Hyperion Financial Management operates, to exploit the security flaw. If successfully exploited, this vulnerability can lead to unauthorized updates, inserts, or deletions of sensitive data accessible within the application. Additionally, it can create conditions for a partial denial of service, affecting the application's availability and user experience. Organizations using this version should implement necessary mitigations to safeguard their data and systems.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.25.0.000

References

CVSS V3.1

Score:
3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.