Security Vulnerability in Oracle Hyperion Financial Management by Oracle
CVE-2026-71147

4.2MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71147?

A security vulnerability exists in the Oracle Hyperion Financial Management product, which can be exploited by unauthenticated attackers with network access through HTTP. Although the exploitation requires human interaction from a third party, successful attacks can lead to unauthorized updates, inserts, or deletions of accessible data within Oracle Hyperion Financial Management. Additionally, attackers may exploit this vulnerability to initiate a partial denial of service, impacting the application's performance. Users should be aware of this security flaw and take the necessary precautions to mitigate potential risks.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.25.0.000

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.