Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage budgets, forecasts, and accounting data. A flaw in its security component allows low-privileged users over the network to access sensitive financial data and potentially disrupt service availability, compromising confidentiality and operational continuity.
Technical details
This is an easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000, likely involving broken access controls or an authentication bypass. The vulnerability is reachable via HTTP from the network and requires only low privileges and no user interaction to exploit. Successful exploitation allows an attacker to access unauthorized critical financial data and cause partial denial of service. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/A:L) indicates high confidentiality impact and low availability impact with no integrity loss. Patch availability from Oracle is expected but details are not yet accessible.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed