Summary
CVE-2026-70854 is a critical vulnerability in the security component of Oracle Hyperion Financial Management. It allows an unauthenticated attacker with network access via HTTP to gain unauthorized creation, deletion, or modification access to critical data, and can also cause the application to crash, resulting in denial of service. The flaw carries a CVSS v3.1 base score of 9.1 (Critical).
Technical details
- Root cause: a flaw in the security component of Oracle Hyperion Financial Management that fails to properly enforce access control on requests.
- Trigger conditions: no authentication or user interaction is required; the attacker only needs network access to the HTTP interface exposed by the application.
- Attack vector: network, over HTTP, with low attack complexity and no privileges required.
- Impact: unauthorized creation, deletion, or modification of critical data (high integrity impact), and the ability to crash the system, causing denial of service (high availability impact). Confidentiality is not affected.
Affected software
- Oracle Hyperion Financial Management, version 11.2.25.0.000
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update for Hyperion released in the August 2026 Critical Security Patch Update Advisory, which addresses CVE-2026-70854.
- If immediate patching is not possible: restrict network access to the Hyperion Financial Management HTTP interface to trusted internal networks only, and monitor for unauthorized data creation, deletion, or modification activity until the patch can be applied.

