Executive brief
Oracle Hyperion Financial Management is a core financial planning and management system used by large enterprises to consolidate financial data and manage reporting. A vulnerability in the security component allows unauthenticated attackers on the network to gain unauthorized access to sensitive financial data and modify records without authentication, potentially exposing confidential financial information and enabling unauthorized changes to critical financial records.
Technical details
This is an authentication bypass or improper access control vulnerability in the security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability is easily exploitable via the network (HTTP) and requires no authentication, credentials, or user interaction. An unauthenticated attacker with network access can compromise the application to read (high confidentiality impact) and modify (limited integrity impact) sensitive financial data. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N) indicates network accessibility, low complexity, and no privileges required. Patch availability status is not confirmed from the advisory text provided.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed