Security Vulnerability in Oracle Hyperion Financial Management by Oracle
CVE-2026-70851

3.1LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70851?

A vulnerability exists in Oracle Hyperion Financial Management, allowing a low privileged attacker with network access via HTTP to potentially compromise the system. The flaw can lead to unauthorized actions, resulting in a partial denial of service, thus affecting the availability of the financial management application. The vulnerability is present in version 11.2.25.0.000 of the product, highlighting the need for users to evaluate their security posture and implement necessary mitigations.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.25.0.000

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.