Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage accounting and budgeting operations. An unauthenticated attacker on the network can exploit a security vulnerability to read, modify, or delete sensitive financial data without authorization, compromising both the confidentiality and integrity of an organization's critical financial records.
Technical details
This is a difficult-to-exploit vulnerability in Oracle Hyperion Financial Management's security component that allows unauthenticated network attackers to compromise the system via TLS. The vulnerability enables unauthorized creation, deletion, and modification of critical data, as well as complete unauthorized access to all accessible data within the product. The attack requires network access but does not require user interaction or authentication. A patch is expected to be available through Oracle's normal security update process; refer to official Oracle security advisories for patching guidance.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed