Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage budgets and close books. An unauthenticated attacker can exploit this vulnerability via HTTP to modify or delete critical financial data, and can also crash the system causing service outage. No authentication or user interaction is required to trigger the attack.
Technical details
This is an unauthenticated network-accessible vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability has an attack vector of HTTP with no authentication required (PR:N), no user interaction (UI:N), and allows an unauthenticated attacker to gain unauthorized access to modify, create, or delete critical data, as well as trigger denial-of-service conditions. The CVSS 3.1 score of 9.1 reflects high impacts to integrity and availability. Patch status and root cause details are not available from the provided advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed