Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage accounting data and reporting. An unauthenticated attacker on the network can exploit a difficult-to-exploit vulnerability in the security component to bypass authentication and gain unauthorized access to create, modify, or delete critical financial data, potentially exposing sensitive accounting records or enabling fraudulent transactions.
Technical details
This is an authentication bypass vulnerability in Oracle Hyperion Financial Management's security component, affecting version 11.2.26.0.000. The vulnerability is remotely exploitable over HTTP without credentials, though it is marked as "difficult to exploit" with high complexity (AC:H). Successful exploitation allows an unauthenticated network-based attacker to achieve both confidentiality and integrity impacts, enabling unauthorized access to all accessible data and creation, deletion, or modification of critical financial records. No patch information is currently available in the advisory; affected organizations should monitor Oracle's security bulletins for remediation guidance.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed