Executive brief
Oracle Hyperion Financial Management is a financial planning and analysis application used by enterprises for budgeting, forecasting, and reporting. An unauthenticated attacker over the network can exploit a security vulnerability to gain unauthorized access to create, modify, or delete financial data, or to read sensitive financial information. The vulnerability impacts both confidentiality and integrity of critical financial records.
Technical details
A difficult-to-exploit vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability is remotely exploitable via HTTPS without authentication; however, it requires specific preconditions (AC:H) to trigger. Successful exploitation allows an attacker to read, create, modify, or delete all accessible financial data within the application. The vulnerability exhibits scope change, meaning attacks on Hyperion Financial Management may also impact other connected systems. No patch information is currently available from the advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed