Executive brief
Oracle Hyperion Financial Management is a critical financial planning and analysis system used by enterprises to manage budgets, forecasts, and financial data. An unauthenticated attacker can bypass security controls and gain unauthorized access to create, modify, or delete sensitive financial data without authentication, directly threatening data integrity, confidentiality, and regulatory compliance.
Technical details
This easily exploitable vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000 allows unauthenticated, remote attackers to compromise the application via TCP network access. The vulnerability exists in the security component and permits unauthorized access to critical data, including creation, deletion, and modification of financial records. No user interaction or elevated privileges are required for successful exploitation. The high CVSS score (9.1) reflects the combination of high confidentiality and integrity impacts with no availability impact. Patch availability and detailed remediation guidance should be obtained from Oracle's security advisories.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed