Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation application used by enterprises to manage budgets, forecasts, and accounting data. A SQL injection vulnerability in the security component allows unauthenticated attackers over the network to read, modify, or delete sensitive financial data, potentially affecting the integrity of accounting records and exposing confidential business information.
Technical details
The vulnerability is a SQL injection flaw in the security component of Oracle Hyperion Financial Management that allows unauthenticated network attackers to execute arbitrary SQL queries. The attack has high complexity but does not require user interaction or privileges. Successful exploitation enables attackers to achieve both confidentiality and integrity impacts, including unauthorized read and modification of critical financial data accessible through the application. Version 11.2.26.0.000 is confirmed affected; patched versions are expected from Oracle as indicated by the CVE publication.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed