Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the security component of Oracle Hyperion Financial Management and can be triggered by an unauthenticated attacker who can reach the system over HTTPS. An attacker who successfully exploits this weakness can create, delete or modify critical data, or gain complete access to all data available to the Hyperion system, thereby compromising confidentiality and integrity. The CVSS base score of 8.7 reflects these significant impacts on data integrity and confidentiality. This does not affect availability. The weakness is a consequence of improper access control or privilege management that allows scope change, meaning an attacker may elevate privileges to affect more data than initially permitted.

Affected Systems

The affected product is Oracle Hyperion Financial Management, version 11.2.26.0.000, as listed under the Oracle product name in the advisory. No other products or versions are explicitly enumerated as affected.

Risk and Exploitability

The CVSS vector indicates an attacker can pursue the flaw over the network with no user interaction and only a high complexity of exploit, but no privileged access is required. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, the scope change still raises the risk because the flaw can be used to alter data beyond the initial compromise window. Consequently, organizations running this version should consider the flaw a high-severity risk until a patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 06:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to a subsequent version of Oracle Hyperion Financial Management that removes the security flaw.
  • Restrict external network access to the Hyperion HTTPS ports to a limited set of trusted IP ranges or implement a VPN gateway so that only authorized administrators can reach the application.
  • Enforce stricter authentication and authorization controls on the Hyperion interfaces, ensuring that no user can create, delete or modify sensitive financial data without explicit privileges.

Generated by OpenCVE AI on September 20, 2026 at 06:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Access Enables Unauthorized Data Modification in Oracle Hyperion Financial Management

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Financial Management Remote Data Modification Vulnerability via HTTPS
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Financial Management Remote Data Modification Vulnerability via HTTPS
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:11:17.265Z

Reserved: 2026-09-08T21:49:12.400Z

Link: CVE-2026-87171

cve-icon Vulnrichment

Updated: 2026-09-18T18:11:11.980Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:04.857

Modified: 2026-09-22T17:15:41.960

Link: CVE-2026-87171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:45:17Z

Weaknesses