Executive brief
Oracle Hyperion Financial Management is a critical financial planning and consolidation tool used by enterprises to manage accounting and reporting. An unauthenticated attacker can exploit a flaw in the HTTP interface to modify, delete, or create financial data without authorization, and cause service interruptions. This directly threatens the integrity of financial records and operational continuity.
Technical details
The vulnerability is an unauthenticated authorization bypass in the Oracle Hyperion Financial Management HTTP interface (component: Security). An attacker with network access can exploit this without authentication or user interaction to gain unauthorized access to critical financial data modification, deletion, and creation operations, as well as trigger partial denial of service. The vulnerability affects version 11.2.26.0.000. Patch status has not been confirmed from available sources.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed