Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation and Full System Compromise
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000 allows a high‑privileged attacker who can reach the system over Oracle Net to compromise the application. Successful exploitation can result in full takeover of the target instance, leading to loss of confidentiality, integrity, and availability of the financial data. The CVSS 3.1 base score of 9.1 indicates a critical rating, and the vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H shows that normal users or the public can initiate the attack, that the attacker only needs low effort, requires high privileges after compromise, and that the vulnerability changes scope to affect other components or products.

Affected Systems

Oracle Corporation’s Hyperion Financial Management application, specifically the 11.2.26.0.000 release. Only this version is listed as affected, but the description notes that attacks may have a broader impact on additional products due to a scope change.

Risk and Exploitability

The critical CVSS score signals a severe risk, while the EPSS < 1 % indicates that exploitation is currently unlikely, although the possibility of future exploitation cannot be dismissed. The vulnerability is not listed in the CISA KEV catalog, yet the combination of an easily exploitable network entry point, high privileges required, and the complete takeover potential warrants serious attention. An attacker would need network access to Oracle Net and sufficient privileges to execute the exploit, after which they could gain full control of the Hyperion system and any integrated components.

Generated by OpenCVE AI on September 17, 2026 at 23:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Review the Oracle security advisory linked in the reference and apply the published patch for Hyperion Financial Management 11.2.26.0.000.
  • Restrict network access to the Oracle Net service by configuring firewalls, VPNs, or application‑level ACLs so that only trusted hosts can reach the affected instance.
  • Implement monitoring and audit logging for authentication, privilege changes, and anomalous activity on the Hyperion environment to detect potential exploitation attempts early.

Generated by OpenCVE AI on September 17, 2026 at 23:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Financial Management Privilege Escalation Vulnerability

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:19.584Z

Reserved: 2026-09-08T21:49:12.401Z

Link: CVE-2026-87189

cve-icon Vulnrichment

Updated: 2026-09-17T12:57:00.327Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:06.840

Modified: 2026-09-22T17:05:21.800

Link: CVE-2026-87189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management