PatchSiren cyber security CVE debrief
CVE-2026-70679 Oracle CVE debrief
The CVE record for CVE-2026-70679 was published on 2026-08-18T21:17:19.720Z and has not been modified since then. The vulnerability affects Oracle Hyperion Calculation Manager version 11.2.25.0.000, specifically the Security component. This vulnerability is easily exploitable by unauthenticated attackers with network access via HTTP, potentially leading to unauthorized update, insert, or delete access to some of Oracle Hyperion Calculation Manager accessible data. The CVSS 3.1 Base Score is 5.3, indicating a Medium severity rating with Integrity impacts. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Organizations using Oracle Hyperion Calculation Manager version 11.2.25.0.000 should prioritize remediation efforts. Security teams and administrators responsible for Oracle Hyperion products should review and apply the necessary patches and implement compensating controls to mitigate the vulnerability.
- Vendor
- Oracle
- Product
- Hyperion Calculation Manager
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-25
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-25
Who should care
Organizations using Oracle Hyperion Calculation Manager version 11.2.25.0.000 should prioritize remediation efforts. Security teams and administrators responsible for Oracle Hyperion products should review and apply the necessary patches and implement compensating controls to mitigate the vulnerability.
Technical summary
The vulnerability in Oracle Hyperion Calculation Manager (component: Security) allows unauthenticated attackers with network access via HTTP to compromise the manager. Successful attacks can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. The CVSS 3.1 Base Score is 5.3 (Integrity impacts). The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Defensive priority
Medium-priority defensive actions are required to address the vulnerability in Oracle Hyperion Calculation Manager. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise the manager, potentially resulting in unauthorized data updates.
Recommended defensive actions
- Review and apply the vendor advisory from Oracle.
- Verify the affected version of Oracle Hyperion Calculation Manager and apply necessary patches.
- Implement compensating controls to monitor and restrict network access to the vulnerable component.
- Conduct regular inventory checks to ensure the vulnerability is remediated.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and NVD details indicate that Oracle Hyperion Calculation Manager version 11.2.25.0.000 is vulnerable. The CVSS score is 5.3, with a Medium severity rating. The vulnerability is easily exploitable and allows unauthenticated attackers to compromise the manager, potentially resulting in unauthorized data updates.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-70679 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-70679
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-70679 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70679
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspuaug2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.