Executive brief
Oracle Hyperion Financial Management is used by enterprises to manage financial planning, consolidation, and reporting. An unauthenticated network attacker can read sensitive financial data without credentials, potentially exposing confidential business information and financial details to competitors or malicious actors.
Technical details
This vulnerability is an unauthorized information disclosure flaw in Oracle Hyperion Financial Management's security component. The vulnerability is easily exploitable and requires only network access via HTTP; no authentication, user interaction, or special configuration is needed. An unauthenticated remote attacker can bypass security controls to read a subset of the application's data. The vulnerability affects version 11.2.25.0.000 and likely earlier versions. Oracle has issued a patch as part of their August 2026 security update.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed