Executive brief
Oracle Hyperion Financial Management is a financial consolidation and planning application used by enterprises to manage complex financial data and reporting. This vulnerability allows an unauthenticated attacker to access the system over the network and view, modify, or delete sensitive financial data without proper credentials, potentially exposing critical business information and enabling unauthorized financial transactions.
Technical details
This is an authentication bypass vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000 that allows unauthenticated network access via HTTP. The vulnerability resides in the security component and permits an attacker to gain unauthorized access to critical data and modify or delete financial records. The attack requires only network access with no authentication or user interaction, making it easily exploitable. Confidentiality and integrity impacts are confirmed, though availability is not affected.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed