Executive brief
Oracle Hyperion Financial Management is a critical financial planning and consolidation system used by enterprises to manage budgets, forecasts, and consolidated financial data. A vulnerability in the Security component allows a low-privileged attacker with network access to gain unauthorized access to sensitive financial data and modify records, potentially compromising an organization's financial records and impacting connected systems.
Technical details
This is an authorization or privilege escalation vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability has low attack complexity and requires only low-level privileges and network access via HTTP to exploit; no user interaction is required. A successful attack allows unauthorized read access to critical financial data and write access (update, insert, delete) to some accessible data. The vulnerability exhibits scope change, meaning the compromise may extend impact beyond the Hyperion Financial Management system to other connected products or infrastructure. Patches or updates should be available from Oracle's security advisories.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed