Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation application used by organizations to manage accounting and reporting. A vulnerability in the security component allows a low-privileged user with local access to the system to gain full control of the application, potentially exposing sensitive financial data and compromising the integrity of financial reporting and operations.
Technical details
This vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. It is an easily exploitable privilege escalation flaw that requires local (adjacent) access and low-privilege user credentials, with no additional user interaction needed. An authenticated local attacker can execute arbitrary actions with elevated privileges, resulting in complete compromise of the application including confidentiality, integrity, and availability of financial data. The CVSS 3.1 score of 7.8 reflects the high impact across all three security dimensions.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed