Executive brief
Oracle Hyperion Financial Management is a widely-used financial planning and consolidation system for enterprise organizations. An unauthenticated attacker with physical access to the network segment containing the system can bypass security controls and gain full administrative control, threatening the confidentiality, integrity, and availability of critical financial data and operations.
Technical details
This vulnerability in the security component of Oracle Hyperion Financial Management (version 11.2.26.0.000) allows unauthenticated attackers with adjacent network access to compromise the system. The attack vector is adjacent (AV:A), requiring physical access to the communication segment, but authentication is not required (PR:N) and no user interaction is needed (UI:N). Successful exploitation results in complete system takeover (full confidentiality, integrity, and availability compromise). The vulnerability is easily exploitable with low attack complexity (AC:L). Patch availability has not been confirmed in the provided advisory text.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed