PatchSiren cyber security CVE debrief
CVE-2026-70960 Oracle Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:54.503Z and has not been modified since then. The vulnerability in Oracle Hyperion Financial Management, a component of Oracle Hyperion, is classified under security and affects version 11.2.25.0.000. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks require human interaction and can lead to unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data, as well as unauthorized update, insert, or delete access to some data. The CVSS 3.1 Base Score is 7.6, indicating high severity with confidentiality and integrity impacts. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). Organizations should verify the affected version, apply patches if available, and implement compensating controls to mitigate potential impact. Evidence from official sources confirms the vulnerability but provides limited details, suggesting further verification is recommended.
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-22
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-22
Who should care
Organizations using Oracle Hyperion Financial Management, particularly those with low-privileged users with network access via HTTP, should review and apply patches if available. Security teams should monitor for suspicious activity and implement compensating controls to mitigate potential impact. Vulnerability management teams should verify the affected version and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Technical summary
A vulnerability in Oracle Hyperion Financial Management allows a low-privileged attacker with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. The supported version that is affected is 11.2.25.0.000. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
Defensive priority
High priority due to high CVSS score of 7.6 and potential for unauthorized access to critical data.
Recommended defensive actions
- Verify the affected version of Oracle Hyperion Financial Management and apply patches if available
- Restrict network access to the affected system
- Monitor for suspicious activity
- Implement compensating controls to mitigate potential impact
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
Evidence from official sources indicates a vulnerability in Oracle Hyperion Financial Management, but details are limited. Further verification is recommended. The CVE record was published on 2026-08-18T21:17:54.503Z and has not been modified since then. The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).
Official resources
-
CVE-2026-70960 CVE record
CVE.org
-
CVE-2026-70960 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:54.503Z and has not been modified since then.