PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-70960 Oracle Corporation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:54.503Z and has not been modified since then. The vulnerability in Oracle Hyperion Financial Management, a component of Oracle Hyperion, is classified under security and affects version 11.2.25.0.000. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks require human interaction and can lead to unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data, as well as unauthorized update, insert, or delete access to some data. The CVSS 3.1 Base Score is 7.6, indicating high severity with confidentiality and integrity impacts. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). Organizations should verify the affected version, apply patches if available, and implement compensating controls to mitigate potential impact. Evidence from official sources confirms the vulnerability but provides limited details, suggesting further verification is recommended.

Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-22
Advisory published
2026-08-18
Advisory updated
2026-08-22

Who should care

Organizations using Oracle Hyperion Financial Management, particularly those with low-privileged users with network access via HTTP, should review and apply patches if available. Security teams should monitor for suspicious activity and implement compensating controls to mitigate potential impact. Vulnerability management teams should verify the affected version and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Technical summary

A vulnerability in Oracle Hyperion Financial Management allows a low-privileged attacker with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. The supported version that is affected is 11.2.25.0.000. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).

Defensive priority

High priority due to high CVSS score of 7.6 and potential for unauthorized access to critical data.

Recommended defensive actions

  • Verify the affected version of Oracle Hyperion Financial Management and apply patches if available
  • Restrict network access to the affected system
  • Monitor for suspicious activity
  • Implement compensating controls to mitigate potential impact
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

Evidence from official sources indicates a vulnerability in Oracle Hyperion Financial Management, but details are limited. Further verification is recommended. The CVE record was published on 2026-08-18T21:17:54.503Z and has not been modified since then. The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:54.503Z and has not been modified since then.