Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation software used by enterprises to manage complex financial data. An unauthenticated attacker can bypass security controls and gain unauthorized access to sensitive financial data, modify records, or delete information without any credentials or user interaction, creating a critical risk to data integrity and confidentiality.
Technical details
This vulnerability allows unauthenticated attackers with network access to compromise Oracle Hyperion Financial Management version 11.2.26.0.000 via a flaw in the security component. The vulnerability is easily exploitable, requiring no user interaction, valid credentials, or complex attack prerequisites—only network connectivity via TCP. Successful exploitation grants attackers unauthorized read access to critical data, as well as write and delete permissions to some accessible data within the application. The attack vector is network-based with no authentication required.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed: Published in NVD and Oracle security alert