Summary
CVE-2026-70921 is a critical, easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management, allowing an unauthenticated attacker with network access via TLS to fully compromise the application. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, as well as complete read access to all data accessible to Oracle Hyperion Financial Management. The flaw carries the maximum CVSS v3.1 base score of 10.0 (Critical) and was disclosed by Oracle in its August 2026 Critical Security Patch Update.
Technical details
- Root cause: A weakness in the "Security" component of Oracle Hyperion Financial Management that fails to properly enforce authentication/authorization controls, permitting unauthorized actions against application data.
- Trigger conditions: No authentication or user interaction is required; an attacker only needs network connectivity to the vulnerable service over TLS.
- Attack vector: Network (AV:N), with low attack complexity (AC:L) and no privileges required (PR:N) — the vulnerability is described by Oracle as "easily exploitable."
- Scope: Changed (S:C) — the vulnerability originates in Oracle Hyperion Financial Management but can significantly impact additional products/components beyond the vulnerable component itself.
- Impact: High confidentiality impact and high integrity impact (complete unauthorized read/write/delete access to all data accessible to the application); no availability impact (A:N).
Affected software
- Oracle Hyperion Financial Management, version 11.2.25.0.000 (as published in the Oracle August 2026 Critical Security Patch Update).
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the security patch for Oracle Hyperion Financial Management released in Oracle’s August 2026 Critical Security Patch Update. Organizations running version 11.2.25.0.000 should update to the fixed release identified in that advisory as soon as possible given the maximum severity score and unauthenticated, network-based exploitation path.
- If immediate patching is not possible: Restrict network access to Oracle Hyperion Financial Management to trusted internal networks/VPN only, remove any direct internet exposure of the service, and monitor for anomalous, unauthenticated requests to the application until the patch can be applied. Oracle strongly recommends applying Critical Patch Update fixes as soon as possible and does not endorse workarounds as a substitute for patching.

