Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage complex accounting and reporting operations. A vulnerability in the Security component allows unauthenticated attackers to gain SSH access to the system and read, modify, or delete sensitive financial data without authorization, potentially compromising the integrity and confidentiality of critical business records.
Technical details
This is an authentication bypass vulnerability in the SSH security component of Oracle Hyperion Financial Management. It allows unauthenticated attackers with network access to bypass authentication controls and gain unauthorized access to the system. The attack is difficult to exploit but requires no user interaction or elevated privileges. Successful exploitation enables attackers to read, modify, or delete financial data and access all accessible information within the system. The vulnerability affects version 11.2.26.0.000; patch availability should be verified with Oracle's security advisories.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed
- other: Reported not exploited in the wild at time of disclosure