PatchSiren cyber security CVE debrief
CVE-2026-70719 Oracle CVE debrief
The CVE-2026-70719 vulnerability affects Oracle Hyperion Calculation Manager version 11.2.25.0.000, allowing unauthenticated attackers with logon access to compromise the manager and gain unauthorized read access to a subset of accessible data. This medium-severity vulnerability has a CVSS score of 4.0. Administrators and security teams should review the CVE record and apply vendor patches. The vulnerability is exploitable, and defenders should verify the affected scope and apply compensating controls.
- Vendor
- Oracle
- Product
- Hyperion Calculation Manager
- CVSS
- MEDIUM 4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-25
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-25
Who should care
Oracle Hyperion Calculation Manager administrators, security teams, and IT professionals responsible for infrastructure security should review the CVE record and apply vendor patches. They should also monitor for unauthorized access attempts and implement compensating controls for logon access. Additionally, they should track exceptions for suspicious activity and review Oracle Hyperion Calculation Manager inventory for version 11.2.25.0.000. Security teams should prioritize patching and verify the affected scope to prevent exploitation. IT professionals should ensure that their infrastructure is secure and up-to-date to prevent similar vulnerabilities in the future. This vulnerability can be mitigated by implementing security best practices and ensuring that all systems are up-to-date with the latest patches and updates. It is essential to have a thorough understanding of the vulnerability and its potential impact on the organization. The vulnerability can be addressed by applying vendor patches and implementing compensating controls. The affected product deployments should be reviewed, and an owner should be assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Monitoring, detection, and logs should be checked for exposed assets that need extra review. Exceptions should be tracked, and remediated assets should be retested before closing the item. Evidence of remediation should be documented. The CVE record provides essential information about the vulnerability, and it is crucial to review it to understand the affected scope and severity. The vendor advisory provides guidance on how to mitigate the vulnerability, and it is essential to follow it to prevent exploitation. The vulnerability can have a significant impact on the organization if not addressed promptly. Therefore, it is crucial to prioritize patching and implement compensating controls to prevent exploitation. The security team should work closely with IT professionals to ensure that the necessary steps are taken,
Technical summary
The CVE-2026-70719 vulnerability affects Oracle Hyperion Calculation Manager version 11.2.25.0.000. It allows unauthenticated attackers with logon access to the infrastructure to compromise the manager and gain unauthorized read access to a subset of accessible data. The CVSS score is 4.0, indicating a medium severity. Defenders should review Oracle Hyperion Calculation Manager inventory, apply vendor patches, and monitor for unauthorized access attempts.
Defensive priority
Review Oracle Hyperion Calculation Manager inventory for version 11.2.25.0.000 and apply vendor patches. Monitor for unauthorized access attempts.
Recommended defensive actions
- Review Oracle Hyperion Calculation Manager inventory for version 11.2.25.0.000
- Apply vendor patches
- Monitor for unauthorized access attempts
- Implement compensating controls for logon access
- Track exceptions for suspicious activity
Evidence notes
The CVE-2026-70719 vulnerability affects Oracle Hyperion Calculation Manager version 11.2.25.0.000. The CVSS score is 4.0, indicating a medium severity. The vulnerability allows unauthenticated attackers with logon access to the infrastructure to compromise the manager and gain unauthorized read access to a subset of accessible data.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-70719 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-70719
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-70719 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70719
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspuaug2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.