Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage budgets and close processes. An unauthenticated attacker with network access can exploit a difficult-to-exploit security flaw to gain unauthorized read access to a subset of sensitive financial data in the system, potentially exposing confidential business information.
Technical details
This vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000 and allows unauthenticated, network-based attack via HTTP. The flaw is difficult to exploit and requires no user interaction. A successful attack results in limited unauthorized read access to a subset of accessible data within the application, impacting confidentiality only (no impact to integrity or availability). The attack vector is network-based (AV:N) with high attack complexity (AC:H), suggesting an exploitation barrier exists but can be overcome by a skilled attacker.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed
- other: CVE-2026-70848