Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation software used by large enterprises to manage budgets and close accounting processes. A vulnerability in its security component allows a high-privileged local attacker to cause a temporary disruption to the system's availability, affecting normal financial operations during an active attack.
Technical details
This is a local privilege-escalation denial-of-service vulnerability in the Security component of Oracle Hyperion Financial Management. The vulnerability requires a high-privileged attacker with logon access to the infrastructure where the product executes, and is classified as difficult to exploit (high complexity). Successful exploitation results in a partial denial of service with only availability impact; no data confidentiality or integrity compromise is possible. The vulnerability affects version 11.2.25.0.000 of Hyperion Financial Management and patches are expected from Oracle's August 2026 security update.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed