Security Flaw in Oracle Hyperion Financial Management by Oracle
CVE-2026-70974

5.3MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70974?

A security flaw exists in Oracle Hyperion Financial Management that enables low-privileged attackers to gain unauthorized access through network HTTP requests. If successfully exploited, this vulnerability can lead to compromise of sensitive data, allowing attackers to manipulate or retrieve critical information stored within the Oracle Hyperion Financial Management environment. The attack vector focuses on network access, making it essential for organizations to mitigate potential risks by applying the recommended security patches and following best practices.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.25.0.000

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.