Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Immediate Patch
AI Analysis

Impact

The Oracle Hyperion Financial Management product contains a flaw in its Security component that permits an unauthenticated attacker with network access over HTTP to bypass authentication and gain unauthorized read or write access to all data available within the application. The vulnerability, classified as CVSS v3.1 8.2, indicates high impact on confidentiality, moderate impact on integrity, and no impact on availability. No user interaction, privilege escalation, or code execution is required; the attacker can directly compromise data confidentiality and integrity through the web interface.

Affected Systems

Oracle Hyperion Financial Management version 11.2.26.0.000 is the only version affected. The flaw is specific to this release and does not apply to earlier or later releases unless they contain the same unpatched component.

Risk and Exploitability

The vulnerability has an EPSS score of less than 1%, indicating a very low probability of exploitation at present. It is not listed in the CISA KEV catalog, meaning no publicly known exploits have been confirmed. The attack vector is network‑based via HTTP, with low attack complexity and no authentication required, allowing any Internet‑reachable host to potentially compromise the system. While the flaw does not provide arbitrary code execution, the ability to read or modify all financial data presents a significant threat to confidentiality and integrity of sensitive business information.

Generated by OpenCVE AI on September 21, 2026 at 18:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Oracle Hyperion Financial Management to a patched version as detailed in Oracle’s security alert https://www.oracle.com/security-alerts/cspusep2026.html
  • Restrict HTTP access to the Hyperion application by firewalling or VPN so only trusted hosts can reach it
  • Enable and review audit logs to detect unauthorized read or write activity inside the application

Generated by OpenCVE AI on September 21, 2026 at 18:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Bypass Enables Unauthorized Data Access in Oracle Hyperion Financial Management

Mon, 21 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Compromise in Oracle Hyperion Financial Management
Weaknesses CWE-285

Mon, 21 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Compromise in Oracle Hyperion Financial Management
Weaknesses CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T19:35:12.519Z

Reserved: 2026-09-08T21:49:12.402Z

Link: CVE-2026-87197

cve-icon Vulnrichment

Updated: 2026-09-21T19:35:04.736Z

cve-icon NVD

Status : Modified

Published: 2026-09-15T20:19:07.777

Modified: 2026-09-21T20:17:38.827

Link: CVE-2026-87197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:00:08Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function