Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage budgets and close processes. This vulnerability allows a low-privileged user with network access to gain unauthorized access to sensitive financial data and potentially disrupt service availability. An attacker could view or modify critical financial information and cause partial service outages.
Technical details
This is a privilege escalation or authorization bypass vulnerability in the Security component of Oracle Hyperion Financial Management. The vulnerability is easily exploitable and requires only low-level privileges and HTTP network access, with no user interaction needed. An attacker can achieve unauthorized read access to all application data and partial denial of service. The affected version is 11.2.26.0.000. Oracle has published a security advisory, though patching details were not available at the time of this analysis.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed