Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage budgets and close processes. This vulnerability allows an unauthenticated attacker with local access to the server to escalate privileges and take over the application, though the attack requires user interaction. A successful exploit could compromise sensitive financial data and disrupt critical business operations.
Technical details
The vulnerability is a privilege escalation flaw in the Security component of Oracle Hyperion Financial Management (version 11.2.25.0.000). It requires local access to the infrastructure where the application runs and is difficult to exploit; successful exploitation also requires user interaction from another person. The attack vector is local (not network-accessible), and an unauthenticated attacker can achieve full compromise of the application with impacts to confidentiality, integrity, and availability. Oracle has issued a patch as part of their August 2026 security update.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed