CVE-2026-70921General(oracle / hyperion_financial_management)

MEDIUMCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch oracle hyperion_financial_management systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hyperion_financial_management

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-19); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
hyperion_financial_management

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-19: 2Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-08-19: 1Exploit Tool / Code · 2026-08-19: 1Patch / Workaround · 2026-08-27: 108-1908-27
Signal classification3 categories
General
133.3%
PoC
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-192
General1PoC1
2026-08-271
Patch1
Full discourse3 posts
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-61241 CVE-2026-70880 CVE-2026-70921 CVE-2026-73343 CVE-2026-75784 ..🧵👇

    Post summary

    The tweet simply lists several CVE identifiers as top vulnerabilities for the day without providing any additional details or actionable information.

    1100041
    35 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-70921 [HIGH PRIORITY] 🔗 https://exploitgrid.net/cve/CVE-2026-70921

    Post summary

    The tweet highlights CVE‑2026‑70921 and links to Exploitgrid, implying that a proof‑of‑concept or exploit code is available, but it does not discuss active exploitation, patches, or technical details.

    1000024
    35 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #Oracle has released security update for Hyperion Financial Management which address a critical vulnerability #CVE-2026-70921. https://www.oracle.com/security-alerts/cspuaug2026.html

    Post summary

    Oracle issued a security update for Hyperion Financial Management to address CVE-2026-70921, indicating a vendor patch is available, but no exploit details or active incidents are mentioned.

    00000292
    8.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclehyperion_financial_management11.2.25.0.000--

Explore more