CVE-2026-70719 Overview
CVE-2026-70719 is an information disclosure vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion. The affected supported version is 11.2.25.0.000, and the flaw resides in the Security component. An unauthenticated attacker with logon access to the infrastructure where Oracle Hyperion Calculation Manager executes can exploit this weakness. Successful exploitation results in unauthorized read access to a subset of data accessible to Oracle Hyperion Calculation Manager. Oracle addressed the issue in its August 2026 Critical Patch Update advisory.
Critical Impact
Local, unauthenticated attackers can obtain unauthorized read access to a subset of Oracle Hyperion Calculation Manager data, resulting in a limited confidentiality breach.
Affected Products
- Oracle Hyperion Calculation Manager 11.2.25.0.000
- Oracle Hyperion (Security component)
- Deployments running the affected supported version on-premises
Discovery Timeline
- 2026-08-18 - CVE-2026-70719 published to the National Vulnerability Database
- 2026-08-20 - Last updated in the NVD database
Technical Details for CVE-2026-70719
Vulnerability Analysis
The vulnerability affects the Security component of Oracle Hyperion Calculation Manager. It allows an attacker who can log on to the infrastructure hosting the application to read a subset of data managed by the product. The issue is classified as an Information Disclosure weakness because the attack impacts confidentiality only, without affecting integrity or availability. Oracle rates exploitation as easy, requiring no privileges and no user interaction on the target application. The EPSS probability is 0.16%, reflecting a low near-term likelihood of observed exploitation activity.
Root Cause
Oracle has not published detailed root-cause information beyond identifying the Security component of Oracle Hyperion Calculation Manager version 11.2.25.0.000 as the affected surface. The behavior is consistent with insufficient access controls that permit unauthorized read access to a subset of application data from a local logon context. Refer to the Oracle Security Alert for vendor-supplied technical details.
Attack Vector
Exploitation requires local access. An attacker must first obtain the ability to log on to the infrastructure where Oracle Hyperion Calculation Manager executes. From that context, the attacker can interact with the Security component without authenticating to the application itself. The attacker then triggers the flaw to read a subset of Oracle Hyperion Calculation Manager data. No user interaction is required, and the scope remains unchanged during exploitation.
No verified proof-of-concept code is publicly available for CVE-2026-70719. The Oracle Security Alert is the authoritative source for exploitation prerequisites and technical detail.
Detection Methods for CVE-2026-70719
Indicators of Compromise
- Unexpected interactive or remote logon sessions on servers hosting Oracle Hyperion Calculation Manager
- Anomalous process execution or file access originating from non-administrative accounts on the Hyperion host
- Access to Calculation Manager configuration or data files by accounts outside the documented administrator group
Detection Strategies
- Correlate host authentication events with subsequent access to Oracle Hyperion Calculation Manager binaries, configuration, and data directories
- Alert on read access to Hyperion Security component files performed by unexpected local users or service accounts
- Baseline normal administrative activity on Hyperion servers and flag deviations, particularly interactive logons from non-admin identities
Monitoring Recommendations
- Enable Windows or Linux audit logging for file reads on Oracle Hyperion Calculation Manager installation directories
- Forward host authentication and file-access telemetry into a centralized SIEM for correlation and retention
- Monitor privileged group membership changes and new local account creation on servers running version 11.2.25.0.000
How to Mitigate CVE-2026-70719
Immediate Actions Required
- Apply the fixes referenced in the Oracle Critical Patch Update Advisory of August 2026
- Inventory all Oracle Hyperion Calculation Manager deployments and identify hosts running 11.2.25.0.000
- Restrict logon rights on Hyperion infrastructure to a minimal set of vetted administrators
Patch Information
Oracle published the fix as part of the August 2026 Critical Patch Update. Administrators should consult the Oracle Security Alert for the specific patch bundle, download instructions, and prerequisites applicable to Oracle Hyperion Calculation Manager 11.2.25.0.000. Apply the update in a test environment first, then roll out to production during a scheduled maintenance window.
Workarounds
- Limit local and remote logon capability on Hyperion servers to trusted administrative accounts only
- Enforce network segmentation so that only authorized management hosts can reach the Hyperion infrastructure
- Increase audit logging of authentication and file-access events on affected servers until the patch is applied
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

