PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-70679 Oracle CVE debrief

The CVE record for CVE-2026-70679 was published on 2026-08-18T21:17:19.720Z and has not been modified since then. The vulnerability affects Oracle Hyperion Calculation Manager version 11.2.25.0.000, specifically the Security component. This vulnerability is easily exploitable by unauthenticated attackers with network access via HTTP, potentially leading to unauthorized update, insert, or delete access to some of Oracle Hyperion Calculation Manager accessible data. The CVSS 3.1 Base Score is 5.3, indicating a Medium severity rating with Integrity impacts. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Organizations using Oracle Hyperion Calculation Manager version 11.2.25.0.000 should prioritize remediation efforts. Security teams and administrators responsible for Oracle Hyperion products should review and apply the necessary patches and implement compensating controls to mitigate the vulnerability.

Vendor
Oracle
Product
Hyperion Calculation Manager
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-25
Advisory published
2026-08-18
Advisory updated
2026-08-25

Who should care

Organizations using Oracle Hyperion Calculation Manager version 11.2.25.0.000 should prioritize remediation efforts. Security teams and administrators responsible for Oracle Hyperion products should review and apply the necessary patches and implement compensating controls to mitigate the vulnerability.

Technical summary

The vulnerability in Oracle Hyperion Calculation Manager (component: Security) allows unauthenticated attackers with network access via HTTP to compromise the manager. Successful attacks can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. The CVSS 3.1 Base Score is 5.3 (Integrity impacts). The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).

Defensive priority

Medium-priority defensive actions are required to address the vulnerability in Oracle Hyperion Calculation Manager. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise the manager, potentially resulting in unauthorized data updates.

Recommended defensive actions

  • Review and apply the vendor advisory from Oracle.
  • Verify the affected version of Oracle Hyperion Calculation Manager and apply necessary patches.
  • Implement compensating controls to monitor and restrict network access to the vulnerable component.
  • Conduct regular inventory checks to ensure the vulnerability is remediated.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record and NVD details indicate that Oracle Hyperion Calculation Manager version 11.2.25.0.000 is vulnerable. The CVSS score is 5.3, with a Medium severity rating. The vulnerability is easily exploitable and allows unauthenticated attackers to compromise the manager, potentially resulting in unauthorized data updates.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-70679 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-70679

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-70679 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70679

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.