Executive brief
Oracle Hyperion Financial Management is a widely-used enterprise financial planning and consolidation platform. A vulnerability in its security component allows a low-privileged attacker with network access to gain complete control over the system, potentially leading to full compromise of financial data, unauthorized modifications, and service disruption.
Technical details
The vulnerability is a privilege escalation flaw in the Security component of Oracle Hyperion Financial Management. It is easily exploitable and requires only network access via HTTP and low privileges to trigger. No user interaction is needed. A successful exploit results in complete system compromise with impact to confidentiality, integrity, and availability. Affected version is 11.2.25.0.000. Oracle has published security guidance in their August 2026 Critical Patch Update advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed
- 2026-08-18: advisory: Oracle Critical Patch Update August 2026