Vulnerability in Oracle Hyperion Financial Management from Oracle
CVE-2026-70854

9.1CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70854?

This vulnerability in Oracle Hyperion Financial Management exposes the product to potential risks where unauthenticated attackers can exploit it over HTTP. The flaw allows for unauthorized actions, including creating, deleting, or modifying sensitive data. Additionally, attackers may affect the availability of the financial management system by inducing repeated crashes, leading to a denial of service. This highlights the critical need for organizations using this product to ensure they are operating on secure versions and to promptly address any security advisories.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.25.0.000

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.