CVE-2026-70738 Overview
CVE-2026-70738 affects the Deployment component of Oracle Hyperion Profitability and Cost Management. The supported version affected is 11.2.25.0.000. A low-privileged attacker with network access via HTTP can exploit this flaw to compromise the application. Successful exploitation leads to unauthorized creation, deletion, or modification of critical data, and unauthorized access to all data accessible through Oracle Hyperion Profitability and Cost Management. Oracle addressed the issue in the August 2026 Critical Patch Update.
Critical Impact
Authenticated network attackers can read and modify all data accessible through Oracle Hyperion Profitability and Cost Management, breaking confidentiality and integrity of financial reporting data.
Affected Products
- Oracle Hyperion Profitability and Cost Management 11.2.25.0.000
- Oracle Hyperion product family (Deployment component)
- Enterprise Performance Management deployments using the affected Hyperion version
Discovery Timeline
- 2026-08-18 - CVE-2026-70738 published to NVD
- 2026-08-20 - Last updated in NVD database
Technical Details for CVE-2026-70738
Vulnerability Analysis
The vulnerability resides in the Deployment component of Oracle Hyperion Profitability and Cost Management. An attacker with low privileges and network reachability to the HTTP interface can compromise the application. The flaw impacts confidentiality and integrity of all data reachable through the product, while availability remains unaffected.
Oracle rates the issue as easily exploitable. No user interaction is required, and exploitation does not require crossing a security scope boundary. Because Hyperion Profitability and Cost Management stores financial planning and cost allocation data, unauthorized modification directly affects financial reporting accuracy.
Root Cause
Oracle has not published root-cause details for CVE-2026-70738. The advisory attributes the weakness to the Deployment component and indicates that a low-privileged authenticated user can subvert intended access controls over HTTP. The impact profile is consistent with a broken access control or authorization flaw within deployment functionality.
Attack Vector
The attack vector is network-based over HTTP. An attacker needs valid low-privileged credentials on the target system and network reachability to the Hyperion Profitability and Cost Management web interface. Once authenticated, the attacker interacts with the Deployment component to read or modify data outside their authorized scope. See the Oracle Security Alert for advisory details.
No public proof-of-concept exploit is available at the time of publication. The EPSS score is 0.365%.
Detection Methods for CVE-2026-70738
Indicators of Compromise
- Unexpected HTTP requests to Hyperion Profitability and Cost Management Deployment endpoints originating from low-privileged user sessions.
- Unauthorized creation, modification, or deletion of Profitability and Cost Management models, rules, or dimensions.
- Authentication events for service or low-privilege accounts followed by administrative-level data access in Hyperion audit logs.
Detection Strategies
- Correlate Hyperion application audit logs with web server access logs to identify privilege mismatches between authenticated roles and requested Deployment operations.
- Baseline expected Deployment component usage and alert on out-of-hours or high-frequency activity by non-administrative accounts.
- Monitor for object-level changes to critical Hyperion artifacts that lack a corresponding change ticket or approved deployment record.
Monitoring Recommendations
- Forward Hyperion middle-tier and WebLogic access logs to a centralized log platform for retention and analytics.
- Enable verbose audit logging on the Deployment component and retain logs for a period consistent with financial audit requirements.
- Alert on any HTTP requests to Deployment URLs from user agents or source IPs not associated with the administrative workflow.
How to Mitigate CVE-2026-70738
Immediate Actions Required
- Apply the fixes provided in the Oracle August 2026 Critical Patch Update to all Oracle Hyperion Profitability and Cost Management 11.2.25.0.000 instances.
- Inventory all Hyperion deployments and confirm which systems expose the Deployment component to internal or external networks.
- Rotate credentials for low-privileged accounts that have HTTP access to the affected application.
Patch Information
Oracle released fixes as part of the August 2026 Critical Patch Update. Administrators should reference the Oracle Security Alert advisory for the specific patch bundle applicable to Hyperion Profitability and Cost Management 11.2.25.0.000 and follow Oracle's documented patching procedures.
Workarounds
- Restrict network access to Hyperion Profitability and Cost Management web endpoints using firewall rules or a reverse proxy that enforces IP allow-lists.
- Require multi-factor authentication for all Hyperion user accounts to raise the cost of credential-based access.
- Review role assignments and remove Deployment component permissions from accounts that do not require them until patching is complete.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

