Executive brief
Oracle Hyperion Financial Management is a widely-used enterprise financial planning and consolidation system. A security flaw in this product allows a low-privilege network attacker to take complete control of the system, potentially compromising all financial data, reports, and operations. The attack requires the attacker to already have valid credentials, but no additional user interaction is needed for exploitation.
Technical details
This is a difficult-to-exploit vulnerability in the security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The attack requires low-privilege credentials and network access via HTTP; however, no user interaction is necessary. Successful exploitation grants an attacker full control over the Hyperion Financial Management system, affecting confidentiality, integrity, and availability of financial data. The CVSS 3.1 Base Score of 7.5 reflects the high impact despite the elevated exploitation difficulty. Patch status and remediation guidance should be obtained directly from Oracle security advisories.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed