Vulnerability in Oracle Hyperion Financial Management Security Component
CVE-2026-71103
6.3MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 18 August 2026
What is CVE-2026-71103?
An improper access control vulnerability exists in the Oracle Hyperion Financial Management product, specifically within its security component. This flaw allows an attacker with low privileges and network access via HTTP to exploit the system, potentially leading to unauthorized updates, deletions, or insertions of accessible data. Additionally, unauthorized reading of certain data may occur, along with the risk of causing a partial denial of service. The vulnerability primarily affects version 11.2.25.0.000, highlighting significant security concerns for users managing sensitive financial data.
Affected Version(s)
Oracle Hyperion Financial Management 11.2.25.0.000