A critical security vulnerability (CVE-2026-70921) has been disclosed in Oracle Hyperion Financial Management, part of the Oracle Hyperion platform. The flaw exists in the Security component and affects version 11.2.25.0.000. Exploitation requires no authentication and can be initiated over TLS, enabling attackers to create, delete, or modify sensitive data. The vulnerability's high CVSS score (10.0) reflects its ease of exploitation and severe impact. Organizations using the affected version are strongly advised to apply vendor-provided patches immediately. Network segmentation and strict access controls should be implemented as interim mitigations. This vulnerability underscores the importance of timely updates for financial management systems exposed to external networks.