Unauthorized Access Vulnerability in Oracle Hyperion Financial Management
CVE-2026-71060

4.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71060?

A security vulnerability has been identified in Oracle's Hyperion Financial Management, specifically within its security component. The issue affects version 11.2.25.0.000, allowing an attacker with high privileges and network access via HTTP to potentially compromise the system. This vulnerability poses a risk of unauthorized access to sensitive data, enabling a successful attack to expose critical information stored within Oracle Hyperion Financial Management.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.25.0.000

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.