Executive brief
Oracle Hyperion Financial Management is an enterprise financial consolidation and reporting system used by organizations to manage critical financial data. A high-privileged attacker with local access to the system can exploit this vulnerability to gain unauthorized access to, modify, or delete sensitive financial data without proper authorization controls.
Technical details
This is a privilege escalation vulnerability in the Security component of Oracle Hyperion Financial Management. The vulnerability is easily exploitable and requires high privilege (administrative) access and local (physical or logical) access to the infrastructure where the product runs. A successful exploit allows an attacker to bypass authorization controls and achieve unauthorized creation, deletion, or modification of critical financial data, as well as unauthorized data access. The vulnerability affects version 11.2.25.0.000. Patches or workarounds from Oracle should be consulted.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed