Vulnerability in Oracle Hyperion Financial Management Security by Oracle
CVE-2026-71090

6.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71090?

A vulnerability exists in Oracle Hyperion Financial Management that allows low-privileged attackers with network access via HTTP to compromise the product. Exploiting this flaw can result in not only denial-of-service (DoS) attacks, causing the application to crash or hang, but also unauthorized access to sensitive data. Attackers may manipulate, read, or alter data, posing significant risks to confidentiality, integrity, and availability. This is particularly concerning for organizations relying on Oracle Hyperion for financial management.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.25.0.000

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.