Executive brief
Oracle Hyperion Financial Management is a financial planning and analysis platform used by enterprises to manage budgeting, forecasting, and reporting. An unauthenticated attacker can trick a legitimate user into visiting a malicious website, which then exploits this vulnerability to create, modify, or delete critical financial data within the system, or cause partial service outages—all without the user's knowledge.
Technical details
This is a cross-site request forgery (CSRF) vulnerability in Oracle Hyperion Financial Management that allows an unauthenticated attacker to perform unauthorized actions via crafted HTTP requests. The vulnerability requires user interaction (the victim must visit a malicious site while logged into Hyperion) and does not require authentication from the attacker themselves. A successful exploit permits unauthorized creation, deletion, or modification of critical financial data, as well as partial denial of service. The vulnerability affects version 11.2.26.0.000 and patches are available from Oracle.
Affected products
- Oracle Hyperion Financial Management 11.2.26.0.000
Timeline
- 2026-09-15: disclosed