Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Tampering and Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability enables a high‑privilege attacker with SQL network access to create, delete or modify critical data in Oracle Hyperion Financial Management. It is exploitable remotely via network‑based SQL interfaces, and the impact includes unauthorized data manipulation and full access to all Hyperion data. CVSS 3.1 score of 8.7 indicates high confidentiality and integrity impact. The weakness lies in the Security component and allows an attacker who already has elevated database privileges to expand their influence, potentially affecting additional related Oracle products. The flaw is essentially an authorization bypass that permits the attacker to perform operations normally restricted to certain roles.

Affected Systems

Oracle Hyperion Financial Management version 11.2.26.0.000, a component of Oracle Corporation’s Hyperion suite, is affected. The Security component in this release is vulnerable and the scope change suggests that other connected Oracle products may also be impacted.

Risk and Exploitability

The CVSS base score of 8.7 indicates serious confidentiality and integrity compromise. However, the EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, suggesting the current likelihood of exploitation is low. Attacks require network access to the Hyperion SQL endpoint and an account with high‑privilege rights. Once successful, the attacker can modify, delete, or capture any data that Hyperion manages and could extend influence to other partner Oracle products due to the noted scope change.

Generated by OpenCVE AI on September 20, 2026 at 05:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s official patch for version 11.2.26.0.000 or upgrade to a newer fixed release.
  • Restrict network access to the Hyperion database engine and enforce least‑privilege SQL user accounts to minimize the potential impact of high‑privilege accounts.
  • Implement monitoring and anomaly detection on SQL activity to promptly detect unauthorized data manipulation attempts.

Generated by OpenCVE AI on September 20, 2026 at 05:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title High‑Privilege Authorization Bypass in Oracle Hyperion Financial Management

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title SQL Privilege Abuse Leading to Data Tampering in Oracle Hyperion Financial Management 11.2.26.0.000
Weaknesses CWE-250
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title SQL Privilege Abuse Leading to Data Tampering in Oracle Hyperion Financial Management 11.2.26.0.000
Weaknesses CWE-250
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:00:53.909Z

Reserved: 2026-09-08T21:49:12.401Z

Link: CVE-2026-87178

cve-icon Vulnrichment

Updated: 2026-09-18T18:00:50.467Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:05.627

Modified: 2026-09-22T17:12:56.407

Link: CVE-2026-87178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:00:14Z

Weaknesses