Executive brief
Oracle Hyperion Financial Management is an enterprise financial planning and consolidation system used by organizations for budgeting, forecasting, and financial reporting. A vulnerability in the security component allows a low-privileged user with network access to gain complete administrative control over the system, potentially exposing or manipulating sensitive financial data, disrupting operations, and compromising the integrity of financial records.
Technical details
This is an easily exploitable vulnerability in the security component of Oracle Hyperion Financial Management that allows a network-accessible, low-privileged attacker to escalate privileges and compromise the system. The vulnerability is reachable via HTTP and requires only low-level user credentials to exploit (PR:L). Successful exploitation results in complete system compromise affecting confidentiality, integrity, and availability. The vulnerability affects version 11.2.26.0.000 of the product. Oracle has released a patch, and the CVSS v3.1 score of 8.8 reflects the high impact of a complete system takeover by an authenticated user.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed