Executive brief
Oracle Hyperion Financial Management is a widely-used enterprise application for budgeting, planning, and financial consolidation. A security vulnerability in version 11.2.26.0.000 allows a low-privileged attacker with local network access to the system to fully compromise the application and gain complete control over its data and operations. This could result in unauthorized access to sensitive financial data, data manipulation, or service disruption.
Technical details
This is an easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management that requires an attacker to be present on the same physical communication segment (adjacent network) and possess low-level privileges. The vulnerability allows unauthenticated or low-privileged network-based exploitation without additional user interaction or complex configuration. Successful exploitation grants complete compromise of the application with high impact to confidentiality, integrity, and availability of financial data and operations. Patches are expected from Oracle in their September 2026 security update, though complete fix details remain unclear due to Oracle's advisory access restrictions.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed