Executive brief
Oracle Hyperion Financial Management is an enterprise financial planning and consolidation platform used by large organizations to manage accounting and budgeting operations. A privilege escalation vulnerability in the Security component allows a high-privileged attacker with network access to take over the system and potentially compromise other connected enterprise applications, affecting confidentiality, integrity, and availability of critical financial data and operations.
Technical details
The vulnerability is an easily exploitable privilege escalation flaw in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The attack requires high-level privileges and network access via Oracle Net protocol, but no user interaction. Successful exploitation allows an attacker to achieve complete system compromise (takeover) with scope change, meaning the impact extends beyond the vulnerable component to affect additional Oracle products on the network. The CVSS 3.1 score of 9.1 reflects critical impact across confidentiality, integrity, and availability. Patch availability should be confirmed via Oracle's official security bulletins.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed