Executive brief
Oracle Hyperion Financial Management is a critical enterprise financial planning and consolidation system used by organizations to manage financial data and reporting. A vulnerability in the security component allows a low-privileged network user to gain unauthorized access to sensitive financial data and cause service disruptions, potentially exposing confidential financial information and compromising business continuity.
Technical details
The vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000 and is exploitable via the HTTP network interface. It requires low privilege credentials and network access, with no user interaction needed. An attacker can achieve unauthorized data access and cause partial denial of service. The vulnerability has a CVSS 3.1 score of 7.1 with impacts to confidentiality (high) and availability (low). No patch information is currently available in the advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed