Executive brief
Oracle Hyperion Financial Management is a widely-used enterprise financial planning and consolidation platform. A vulnerability in its security component allows a low-privileged user with network access to take complete control of the application, compromising all stored financial data and operational integrity. This can lead to unauthorized access to sensitive financial records, data manipulation, and operational disruption.
Technical details
A privilege escalation vulnerability exists in the Oracle Hyperion Financial Management security component, affecting version 11.2.26.0.000. The vulnerability is easily exploitable by an authenticated (low-privileged) attacker via the HTTP interface without requiring user interaction. No additional complex conditions are needed to trigger the flaw. Successful exploitation grants an attacker complete system control, including the ability to read, modify, or delete all data and configurations (C:H, I:H, A:H impact). The attack vector is network-based, accessible to any user with valid low-privilege credentials.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed