Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-70719

CVE-2026-70719: Oracle Hyperion Information Disclosure Flaw

CVE-2026-70719 is an information disclosure vulnerability in Oracle Hyperion Calculation Manager that allows unauthorized data access. This article covers technical details, affected versions, impact analysis, and mitigation.

Published:

CVE-2026-70719 Overview

CVE-2026-70719 is an information disclosure vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion. The affected supported version is 11.2.25.0.000, and the flaw resides in the Security component. An unauthenticated attacker with logon access to the infrastructure where Oracle Hyperion Calculation Manager executes can exploit this weakness. Successful exploitation results in unauthorized read access to a subset of data accessible to Oracle Hyperion Calculation Manager. Oracle addressed the issue in its August 2026 Critical Patch Update advisory.

Critical Impact

Local, unauthenticated attackers can obtain unauthorized read access to a subset of Oracle Hyperion Calculation Manager data, resulting in a limited confidentiality breach.

Affected Products

  • Oracle Hyperion Calculation Manager 11.2.25.0.000
  • Oracle Hyperion (Security component)
  • Deployments running the affected supported version on-premises

Discovery Timeline

  • 2026-08-18 - CVE-2026-70719 published to the National Vulnerability Database
  • 2026-08-20 - Last updated in the NVD database

Technical Details for CVE-2026-70719

Vulnerability Analysis

The vulnerability affects the Security component of Oracle Hyperion Calculation Manager. It allows an attacker who can log on to the infrastructure hosting the application to read a subset of data managed by the product. The issue is classified as an Information Disclosure weakness because the attack impacts confidentiality only, without affecting integrity or availability. Oracle rates exploitation as easy, requiring no privileges and no user interaction on the target application. The EPSS probability is 0.16%, reflecting a low near-term likelihood of observed exploitation activity.

Root Cause

Oracle has not published detailed root-cause information beyond identifying the Security component of Oracle Hyperion Calculation Manager version 11.2.25.0.000 as the affected surface. The behavior is consistent with insufficient access controls that permit unauthorized read access to a subset of application data from a local logon context. Refer to the Oracle Security Alert for vendor-supplied technical details.

Attack Vector

Exploitation requires local access. An attacker must first obtain the ability to log on to the infrastructure where Oracle Hyperion Calculation Manager executes. From that context, the attacker can interact with the Security component without authenticating to the application itself. The attacker then triggers the flaw to read a subset of Oracle Hyperion Calculation Manager data. No user interaction is required, and the scope remains unchanged during exploitation.

No verified proof-of-concept code is publicly available for CVE-2026-70719. The Oracle Security Alert is the authoritative source for exploitation prerequisites and technical detail.

Detection Methods for CVE-2026-70719

Indicators of Compromise

  • Unexpected interactive or remote logon sessions on servers hosting Oracle Hyperion Calculation Manager
  • Anomalous process execution or file access originating from non-administrative accounts on the Hyperion host
  • Access to Calculation Manager configuration or data files by accounts outside the documented administrator group

Detection Strategies

  • Correlate host authentication events with subsequent access to Oracle Hyperion Calculation Manager binaries, configuration, and data directories
  • Alert on read access to Hyperion Security component files performed by unexpected local users or service accounts
  • Baseline normal administrative activity on Hyperion servers and flag deviations, particularly interactive logons from non-admin identities

Monitoring Recommendations

  • Enable Windows or Linux audit logging for file reads on Oracle Hyperion Calculation Manager installation directories
  • Forward host authentication and file-access telemetry into a centralized SIEM for correlation and retention
  • Monitor privileged group membership changes and new local account creation on servers running version 11.2.25.0.000

How to Mitigate CVE-2026-70719

Immediate Actions Required

  • Apply the fixes referenced in the Oracle Critical Patch Update Advisory of August 2026
  • Inventory all Oracle Hyperion Calculation Manager deployments and identify hosts running 11.2.25.0.000
  • Restrict logon rights on Hyperion infrastructure to a minimal set of vetted administrators

Patch Information

Oracle published the fix as part of the August 2026 Critical Patch Update. Administrators should consult the Oracle Security Alert for the specific patch bundle, download instructions, and prerequisites applicable to Oracle Hyperion Calculation Manager 11.2.25.0.000. Apply the update in a test environment first, then roll out to production during a scheduled maintenance window.

Workarounds

  • Limit local and remote logon capability on Hyperion servers to trusted administrative accounts only
  • Enforce network segmentation so that only authorized management hosts can reach the Hyperion infrastructure
  • Increase audit logging of authentication and file-access events on affected servers until the patch is applied

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.