Summary
CVE-2026-70739 is a critical vulnerability in the Server component of Oracle Hyperion Financial Reporting that allows a completely unauthenticated, remote attacker to fully compromise the affected system over HTTP. The flaw requires no user interaction and no privileges, and its exploitation results in a total loss of confidentiality, integrity, and availability of the underlying host. Oracle disclosed the issue in its August 2026 Critical Patch Update, rating it 9.8 (Critical) under CVSS v3.1.
Technical details
- Root cause: The vulnerability resides in the Server component of Oracle Hyperion Financial Reporting; Oracle’s advisory characterizes it as easily exploitable and capable of resulting in complete takeover of the product.
- Trigger conditions: No authentication, no special user privileges, and no user interaction are required to trigger the flaw.
- Attack vector: Remote, network-based exploitation via HTTP, meaning any attacker with network access to the exposed Hyperion Financial Reporting service can attempt exploitation without needing valid credentials.
- Impact: Successful exploitation grants the attacker full control ("complete compromise") over Oracle Hyperion Financial Reporting, with high impact to confidentiality, integrity, and availability of the affected system — effectively a critical remote takeover scenario.
Affected software
- Oracle Hyperion Financial Reporting, version 11.2.25.0.000
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the security patch provided in Oracle’s August 2026 Critical Patch Update for Oracle Hyperion Financial Reporting version 11.2.25.0.000. Organizations should prioritize this update given the unauthenticated, network-exploitable nature of the flaw.
- If patching cannot be performed immediately: Restrict network access to Oracle Hyperion Financial Reporting servers — do not expose the service directly to the internet, and limit access to trusted internal networks or via VPN until the patch is applied. Monitor HTTP access logs for anomalous or unauthenticated requests to the Financial Reporting service as an interim compensating control.

