Executive brief
Oracle Hyperion Financial Management is a financial consolidation and reporting tool used by enterprises to manage accounting data and close processes. A vulnerability allows an attacker with low-level network access to bypass authentication controls and gain unauthorized access to sensitive financial data, potentially exposing complete account information across multiple systems.
Technical details
This vulnerability in the Security component of Oracle Hyperion Financial Management allows low-privileged attackers to bypass authentication controls via HTTP with no additional user interaction required. The flaw is easily exploitable and accessible over the network to any authenticated (low-privilege) user. Successful exploitation results in unauthorized access to critical financial data with high confidentiality impact and scope change affecting downstream systems. The vulnerability affects version 11.2.25.0.000 and patches are expected from Oracle's August 2026 CPU update.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed