PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-70746 Oracle CVE debrief

The CVE-2026-70746 vulnerability affects Oracle Hyperion Financial Reporting version 11.2.25.0.000, allowing unauthenticated attackers with network access via HTTP to compromise the system. This vulnerability has a high CVSS severity score of 8.1, impacting confidentiality and integrity. Organizations should verify their deployments and apply patches. The vulnerability requires human interaction and can result in unauthorized creation, deletion, or modification access to critical data. Evidence limits suggest focusing on defensive priorities and compensating controls. The CVE record was published on 2026-08-18T21:17:27.450Z and has not been modified since then.

Vendor
Oracle
Product
Hyperion Financial Reporting
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-25
Advisory published
2026-08-18
Advisory updated
2026-08-25

Who should care

Organizations using Oracle Hyperion Financial Reporting version 11.2.25.0.000 should prioritize patching this vulnerability. Security teams and vulnerability management teams should review and apply patches. Operators and administrators of affected systems should be aware of the potential risks and take necessary precautions. This includes verifying their deployments, applying patches, and monitoring for suspicious activity.

Technical summary

CVE-2026-70746 is a vulnerability in Oracle Hyperion Financial Reporting, specifically in the Server component. The vulnerability has a CVSS 3.1 score of 8.1 and can allow unauthenticated attackers with network access via HTTP to compromise the system, impacting confidentiality and integrity. Successful attacks require human interaction from a person other than the attacker. The supported version that is affected is 11.2.25.0.000. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).

Defensive priority

Oracle Hyperion Financial Reporting vulnerability allows unauthenticated attackers to compromise data integrity and confidentiality.

Recommended defensive actions

  • Review and apply Oracle's security patches for Hyperion Financial Reporting
  • Restrict network access to Hyperion Financial Reporting
  • Monitor for suspicious activity
  • Verify and limit human interaction requirements
  • Conduct a thorough review of the affected system to identify potential security risks
  • Implement compensating controls to mitigate the vulnerability
  • Track and monitor the system for any signs of exploitation

Evidence notes

The CVE-2026-70746 vulnerability affects Oracle Hyperion Financial Reporting version 11.2.25.0.000. Successful attacks require human interaction. CVSS 3.1 score: 8.1. The vulnerability has a high CVSS severity score. Organizations should verify their deployments and apply patches. Evidence limits suggest focusing on defensive priorities and compensating controls.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-70746 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-70746

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-70746 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70746

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.