Executive brief
Oracle Hyperion Financial Management is a financial planning and analysis system used by enterprises to manage budgeting, forecasting, and consolidation processes. An unauthenticated attacker with network access can bypass security controls to read, modify, or delete sensitive financial data without proper authorization. Successful exploitation could expose or corrupt critical financial records and compromise the integrity of financial reporting.
Technical details
This vulnerability is a difficult-to-exploit authentication bypass in the security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability is accessible over the network via TLS to unauthenticated attackers without requiring user interaction. Successful exploitation allows an attacker to achieve both confidentiality and integrity impacts, enabling unauthorized access to and modification of all financial data accessible through the application. No patch information is currently available from the provided advisory references.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed