Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation software used by organizations to manage accounting and reporting. An unauthenticated attacker can gain unauthorized access to critical financial data over the network without providing credentials, potentially exposing sensitive company financial records and consolidated reporting data.
Technical details
This is an authentication bypass or authorization vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The flaw is easily exploitable and requires no user interaction; an attacker with network access can send crafted HTTP requests to bypass authentication controls. Successful exploitation allows unauthorized data disclosure with high confidentiality impact but does not affect data integrity or system availability. A patch is expected from Oracle; check the September 2026 Critical Patch Update for details.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed