Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage accounting and reporting. An unauthenticated network attacker can exploit this vulnerability to read, create, delete, or modify critical financial data without authorization, potentially compromising financial records and regulatory compliance.
Technical details
This is an authentication bypass vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability is easily exploitable and requires only network access via HTTP, with no authentication, user interaction, or special conditions. A remote unauthenticated attacker can achieve unauthorized read access to a subset of data and high-impact write/modify/delete access to critical data. The CVSS 3.1 vector indicates low confidentiality impact and high integrity impact with no availability impact. Patch status and specific technical root cause details are not disclosed in available sources.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed