Summary
CVE-2026-70741 is a critical vulnerability in the Server component of Oracle Hyperion Financial Reporting. It allows an unauthenticated attacker with network access via RMI to compromise the application, gaining unauthorized creation, deletion, or modification access to critical data and complete access to all data accessible within Hyperion Financial Reporting. Oracle rates this as CRITICAL with a CVSS 3.1 base score of 9.1.
Technical details
- Root cause: an exploitable flaw in the Hyperion Financial Reporting Server component reachable over the RMI protocol.
- Trigger conditions: no authentication or user interaction is required; the attacker only needs network access to the RMI service exposed by the affected component.
- Attack vector: network-based (AV:N), low attack complexity (AC:L).
- Impact: high confidentiality impact and high integrity impact — unauthorized creation, deletion, or modification of data and full read access to data accessible through the application. No availability impact reported.
Affected software
- Oracle Hyperion Financial Reporting, version 11.2.25.0.000
Severity
- CVSS 3.1 Base Score: 9.1 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update that addresses this vulnerability for Oracle Hyperion Financial Reporting 11.2.25.0.000. Consult Oracle’s published security advisory for the specific patch identifier and apply it as soon as possible.
- If immediate patching is not possible: Restrict network access to the RMI service used by Hyperion Financial Reporting (e.g., via firewall rules or network segmentation) so it is not reachable from untrusted networks, and monitor for unexpected RMI connections until the patch can be applied.

