Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage budgets and close operations. An authentication bypass vulnerability allows an attacker to access the platform over the network without credentials and read sensitive financial data. Exploiting this flaw could expose critical company financial information and operational details.
Technical details
This is an authentication bypass or authorization flaw in the Security component of Oracle Hyperion Financial Management. The vulnerability is easily exploitable and requires only network access via HTTP—no authentication or user interaction is needed. An unauthenticated attacker can achieve unauthorized access to critical financial data and potentially read all accessible data within the application. The affected version is 11.2.26.0.000. Oracle has published security advisories addressing this issue; patching is recommended.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed