Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage critical financial data. A vulnerability in the security component allows low-privilege users with network access to gain unauthorized access to sensitive financial data and partially disrupt service availability. The exploit requires valid credentials but no complex interaction, making it a significant risk to organizations relying on this system.
Technical details
This is an authentication or authorization bypass vulnerability in Oracle Hyperion Financial Management 11.2.25.0.000, located in the security component. The vulnerability is easily exploitable via HTTP by a low-privileged, authenticated attacker with network access. No user interaction or complex configuration is required. A successful exploit can lead to unauthorized disclosure of all accessible financial data (high confidentiality impact) and a partial denial of service condition (low availability impact). Patch status and specific fix availability are not detailed in the advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed
- other: Reported as CVE-2026-70934