Executive brief
Oracle Hyperion Financial Management is a financial planning and analysis system used by enterprises to manage budgeting, forecasting, and reporting. A flaw in the security component allows a low-privilege authenticated attacker with network access to view, modify, or delete sensitive financial data without proper authorization, potentially compromising the confidentiality and integrity of critical business information.
Technical details
This is an authorization bypass vulnerability in Oracle Hyperion Financial Management (version 11.2.26.0.000) affecting the security component. The vulnerability is exploitable over HTTP and requires low privilege user credentials and network access to the application. An attacker can achieve unauthorized access to, modification of, or deletion of critical financial data within the system. No active exploitation in the wild has been reported as of the advisory date; patches are expected from Oracle.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed