Executive brief
Oracle Hyperion Financial Management is a financial planning and analysis application used by enterprises to manage budgets and consolidate financial data. A vulnerability in the security component allows an authenticated attacker with administrative privileges to access sensitive financial data and potentially disrupt service operations through the network.
Technical details
The vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000 and is remotely exploitable via HTTP. It requires high-level privilege (administrator) but no additional user interaction. The issue results in a scope change, meaning successful exploitation can impact systems beyond Hyperion itself. An attacker can gain unauthorized access to confidential financial data and cause partial denial of service. The vulnerability is easily exploitable due to low attack complexity (AC:L). A fix or patch is expected as part of Oracle's standard security update cycle.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed