Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage budgets and close processes. An unauthenticated attacker can exploit a security flaw over the network to modify financial data, insert unauthorized transactions, or disrupt service availability. This could enable unauthorized financial manipulation or prevent legitimate users from accessing critical financial systems.
Technical details
This is an unauthenticated remote vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. The vulnerability is easily exploitable via HTTP network access without authentication or user interaction required. Successful exploitation allows an attacker to execute unauthorized update, insert, or delete operations on accessible financial data and cause partial denial of service. The root cause and technical mechanism are not disclosed in available references, but the attack vector is network-based with no access controls required.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed
- 2026-08-18: advisory