Executive brief
Oracle Hyperion Financial Management is an enterprise financial planning and consolidation platform used by large organizations to manage accounting data and close processes. An unauthenticated network attacker can bypass security controls and gain unauthorized access to create, delete, or modify critical financial data, or read all accessible data in the system. This could enable fraud, data manipulation, or complete exposure of confidential financial information.
Technical details
This is an authentication bypass vulnerability in the security component of Oracle Hyperion Financial Management 11.2.26.0.000. The flaw allows unauthenticated attackers to exploit the system via TCP network access without providing valid credentials. Successful exploitation enables unauthorized CRUD operations on critical financial data and complete read access to all accessible information within the application. The vulnerability is easily exploitable and requires no user interaction or special preconditions. Oracle has assigned this a CVSS 3.1 score of 9.1 with high confidentiality and integrity impacts.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed