Executive brief
Oracle Hyperion Financial Management is a critical financial planning and consolidation system used by enterprises to manage budgets, accounts, and financial data. This vulnerability allows an attacker with physical access to the network segment where the system operates to bypass authentication and read, modify, or delete sensitive financial data without authorization. Organizations relying on this system for financial reporting face potential data integrity breaches and unauthorized access to confidential financial information.
Technical details
This is an authentication bypass or credential compromise vulnerability in Oracle Hyperion Financial Management's security component. The vulnerability is triggered over an adjacent network segment (local area network), requiring physical proximity to the network infrastructure but no user authentication or interaction. An unauthenticated attacker positioned on the same network segment can achieve both confidentiality and integrity impacts, allowing unauthorized access to and modification of critical financial data. The vulnerability affects version 11.2.25.0.000, and patches or mitigations from Oracle should be consulted.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed