Security Vulnerability in Oracle Hyperion Financial Management by Oracle
CVE-2026-71145

4.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71145?

A vulnerability exists in Oracle Hyperion Financial Management that could allow a low privileged attacker with network access via HTTP to compromise the product. Attackers must rely on human interaction from a victim to successfully exploit this vulnerability. This issue potentially affects additional products, as successful exploitation may allow unauthorized updates, inserts, or deletions of accessible data, as well as unauthorized reading of certain data within Oracle Hyperion Financial Management.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.25.0.000

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.