Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation application used by enterprises to manage budgets and reporting. A vulnerability in the security component allows low-privileged network users to bypass authorization controls, exposing sensitive financial data and potentially disrupting service availability.
Technical details
This is a privilege escalation vulnerability in the security component of Oracle Hyperion Financial Management affecting version 11.2.26.0.000. The vulnerability is easily exploitable via HTTP by an unauthenticated or low-privileged network attacker without requiring user interaction. Successful exploitation allows attackers to gain unauthorized access to critical financial data and execute partial denial-of-service attacks. The CVSS 3.1 score of 7.1 reflects high confidentiality impact and low availability impact.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed