CVE-2026-70733 Overview
CVE-2026-70733 is an access control vulnerability [CWE-284] in the Deployment component of Oracle Hyperion Profitability and Cost Management. The affected version is 11.2.25.0.000. A low-privileged attacker with network access via HTTP can exploit this issue to compromise the application. Successful exploitation leads to unauthorized access to critical data and a partial denial of service. Oracle published the advisory as part of the August 2026 Critical Patch Update.
Critical Impact
Authenticated network attackers can read all data accessible to Oracle Hyperion Profitability and Cost Management and cause a partial denial of service.
Affected Products
- Oracle Hyperion Profitability and Cost Management
- Affected version: 11.2.25.0.000
- Component: Deployment
Discovery Timeline
- 2026-08-18 - CVE-2026-70733 published to NVD
- 2026-08-20 - Last updated in NVD database
Technical Details for CVE-2026-70733
Vulnerability Analysis
The vulnerability resides in the Deployment component of Oracle Hyperion Profitability and Cost Management. Oracle categorizes the issue under improper access control [CWE-284]. An attacker who already holds low-level credentials can send crafted HTTP requests to reach functionality that should be restricted. The result is disclosure of confidential data and disruption of service availability.
Exploitation does not require user interaction and does not cross a trust boundary beyond the vulnerable component. Data integrity is not impacted, but confidentiality is fully compromised. The EPSS probability is 0.348%.
Root Cause
The root cause is insufficient authorization enforcement inside the Deployment component. Access decisions rely on controls that do not adequately restrict low-privileged accounts from sensitive operations. Because the flaw sits in the deployment workflow, standard tenant or role boundaries can be crossed by authenticated users. Oracle has not publicly released code-level details of the defect.
Attack Vector
The attack vector is network-based (AV:N) over HTTP. An attacker must first authenticate as a low-privileged user to Oracle Hyperion Profitability and Cost Management. From there, the attacker issues HTTP requests to the Deployment component to trigger the flaw. No user interaction is required, and exploitation complexity is low.
No public proof-of-concept exploit is available. CISA has not listed CVE-2026-70733 in the Known Exploited Vulnerabilities catalog. Refer to the Oracle Security Alert for vendor guidance.
Detection Methods for CVE-2026-70733
Indicators of Compromise
- Unexpected HTTP requests from low-privileged Hyperion accounts to Deployment endpoints.
- Anomalous data export or read activity by service or business-user accounts.
- Application errors or partial service degradation correlated with unusual authenticated sessions.
Detection Strategies
- Enable verbose application logging on the Deployment component and forward events to a centralized SIEM.
- Baseline normal HTTP request patterns per Hyperion role and alert on deviations.
- Correlate authentication logs with data access events to identify low-privileged users touching sensitive deployment resources.
Monitoring Recommendations
- Monitor Oracle Hyperion audit logs for privilege boundary crossings.
- Track HTTP response codes and payload sizes on Deployment endpoints for unusual spikes.
- Alert on repeated failed or partial denial-of-service conditions affecting Hyperion services.
How to Mitigate CVE-2026-70733
Immediate Actions Required
- Apply the fixes published in the Oracle August 2026 Critical Patch Update.
- Inventory all Oracle Hyperion Profitability and Cost Management instances running 11.2.25.0.000.
- Review and reduce the number of low-privileged accounts with network access to Hyperion.
Patch Information
Oracle addressed CVE-2026-70733 in the August 2026 Critical Patch Update security alert. Administrators should follow the vendor advisory to obtain and deploy the corresponding patch for Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000. Validate patch application in a staging environment before production rollout.
Workarounds
- Restrict HTTP access to Oracle Hyperion Profitability and Cost Management to trusted network segments.
- Enforce multi-factor authentication and strong password policies on all Hyperion accounts.
- Audit and revoke unnecessary role assignments that grant access to the Deployment component.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

