Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation application used by organizations to manage complex financial processes. An attacker without authentication can exploit a SQL injection vulnerability via network access to take complete control of the application, compromising all financial data, reporting integrity, and system availability.
Technical details
This is a SQL injection vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability is easily exploitable and requires only network access with no authentication or user interaction needed. An unauthenticated remote attacker can inject arbitrary SQL commands to fully compromise the application, resulting in unauthorized access to confidential financial data, modification of financial records, and denial of service. A patch is available from Oracle's September 2026 security advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed