Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The issue is located in the Security component of Oracle Hyperion Financial Management. An attacker who has only low-privileged credentials and can reach the system over standard HTTP is able to fully control the target, compromising confidentiality, integrity, and availability. Because the vulnerability includes a scope change, it may also affect other Oracle products that share components or configurations.

Affected Systems

Oracle Hyperion Financial Management version 11.2.26.0.000 is affected. The vulnerability may also extend to additional Oracle products through a scope change, potentially broadening its impact.

Risk and Exploitability

The CVSS 3.1 base score of 9.9 classifies the flaw as critical, indicating that a successful attack would grant complete control of the affected Hyperion instance. The EPSS score is reported as less than 1%, suggesting a low estimated probability of exploitation in the wild, yet the flaw remains technically highly exploitable with only standard HTTP access and low-privileged credentials. Although the vulnerability is not currently listed in the CISA KEV catalog, the combination of severe impact and easily satisfied network prerequisites highlights the importance of timely remediation.

Generated by OpenCVE AI on September 20, 2026 at 06:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor‑issued patch or update for Oracle Hyperion Financial Management 11.2.26.0.000.
  • Restrict direct HTTP access to the Hyperion instance—deploy firewall rules, VPNs, or application‑layer gateways to limit exposure to trusted networks only.
  • If a patch cannot be deployed immediately, consider disabling or removing the exposed HTTP interface to block exploitation until remediation can be completed.
  • Continuously monitor HTTP traffic and logs for signs of exploitation attempts or anomalous activity.

Generated by OpenCVE AI on September 20, 2026 at 06:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Financial Management 11.2.26.0.000 Remote Code Execution via Low-Privileged HTTP Access

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title HTTP‑Based Exploit Enables Takeover of Oracle Hyperion Financial Management
Weaknesses CWE-284
CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title HTTP‑Based Exploit Enables Takeover of Oracle Hyperion Financial Management
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:20.781Z

Reserved: 2026-09-08T21:49:12.400Z

Link: CVE-2026-87172

cve-icon Vulnrichment

Updated: 2026-09-17T12:57:28.771Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:04.970

Modified: 2026-09-22T17:15:24.270

Link: CVE-2026-87172

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:45:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management