Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Takeover through physical access
Action: Patch Immediately
AI Analysis

Impact

The Oracle Hyperion Financial Management 11.2.26.0.000 vulnerability is triggered by an unauthenticated attacker who can physically reach the communication segment on the host hardware. Exploitation bypasses authentication (CWE‑269) and grants full control of the application, leading to a compromise of confidentiality, integrity, and availability. The weakness permits taking over the entire application without any user interaction, and the identification of a scope change means that other connected Oracle products could also be affected if the same hardware is used to host them.

Affected Systems

Oracle Hyperion Financial Management version 11.2.26.0.000 is the only product and version explicitly listed as vulnerable; no other releases are indicated in the advisory.

Risk and Exploitability

The CVSS base score of 9.6 signals critical severity, while the EPSS score of less than 1% indicates that the current likelihood of exploitation is low. Nonetheless, physical access to the server’s network segment eliminates the need for network connectivity or privileged accounts, making a successful attack both plausible and devastating. The vulnerability is not present in the CISA KEV catalog.

Generated by OpenCVE AI on September 20, 2026 at 06:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for Oracle Hyperion Financial Management 11.2.26.0.000 immediately.
  • Limit physical access to the machine hosting the Hyperion application by implementing access controls, badge readers, or locking the server room.
  • Review and isolate any non-essential services on the affected hardware to reduce attack surface and conduct continuous monitoring of audit logs for suspicious activity.

Generated by OpenCVE AI on September 20, 2026 at 06:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Physical Access Enables Full Application Takeover in Oracle Hyperion Financial Management

Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Access Enables Takeover of Oracle Hyperion Financial Management
Weaknesses CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Access Enables Takeover of Oracle Hyperion Financial Management
Weaknesses CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:19.873Z

Reserved: 2026-09-08T21:49:12.401Z

Link: CVE-2026-87186

cve-icon Vulnrichment

Updated: 2026-09-17T12:57:07.360Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:06.507

Modified: 2026-09-22T17:06:24.170

Link: CVE-2026-87186

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:45:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management