Oracle Hyperion Financial Management Security Vulnerability
CVE-2026-71149

4.2MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71149?

A security flaw in Oracle Hyperion Financial Management allows a low-privileged attacker with access to the infrastructure to compromise sensitive data. This vulnerability, while difficult to exploit, requires interaction from a third party. Successful attempts can lead to unauthorized modifications, deletions, and partial denial of service, impacting the confidentiality, integrity, and availability of the data handled by Oracle Hyperion Financial Management. Organizations using version 11.2.25.0.000 should take immediate precautions to mitigate potential risks.

Affected Version(s)

Oracle Hyperion Financial Management 11.2.25.0.000

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.