Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation leading to full takeover of Oracle Hyperion Financial Management
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is located in the Security component of Oracle Hyperion Financial Management. An attacker who already has local logon credentials of low privilege can exploit this flaw to compromise the entire Hyperion instance. The flaw allows bypassing built‑in access controls and grants full confidentiality, integrity, and availability damage. It is represented by a local attack vector and can lead to a complete takeover of the application.

Affected Systems

Oracle Hyperion Financial Management version 11.2.26.0.000 is the identified affected release. The CVSS vector notes a scope change, indicating that a corruption of Hyperion could potentially impact other Oracle products or modules that share the same infrastructure.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 marks this as a high‑severity vulnerability, though the EPSS score is reported as < 1 %, suggesting a low likelihood of exploitation in the short term. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local or low‑privileged access to the server running Hyperion, and the exploit does not require network interaction. The S:C vector indicates that while the flaw originates in Hyperion, compromise could hypothetically affect other products that share the same environment.

Generated by OpenCVE AI on September 20, 2026 at 05:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle security patch or upgrade to a fixed version of Hyperion as detailed in the Oracle Security Alert (https://www.oracle.com/security-alerts/cspusep2026.html).
  • Restrict local accounts that can log on to the Hyperion servers and enforce the principle of least privilege by removing unnecessary or unused accounts.
  • Disable unused ports and services on the Hyperion servers and isolate them from the public network to limit local compromise opportunities.
  • Monitor server logs and authentication events for anomalous activity that could indicate an exploitation attempt.

Generated by OpenCVE AI on September 20, 2026 at 05:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Vulnerability in Oracle Hyperion Financial Management

Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Hyperion Financial Management Local Privilege Escalation Leading to Full Takeover
Weaknesses CWE-284
CWE-732

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Hyperion Financial Management Local Privilege Escalation Leading to Full Takeover
Weaknesses CWE-284
CWE-732

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T12:50:09.894Z

Reserved: 2026-09-08T21:49:12.401Z

Link: CVE-2026-87182

cve-icon Vulnrichment

Updated: 2026-09-17T12:49:53.626Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:06.067

Modified: 2026-09-22T17:11:28.163

Link: CVE-2026-87182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:00:14Z

Weaknesses
  • CWE-269

    Improper Privilege Management