Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data manipulation and disclosure in Oracle Hyperion Financial Management via an unauthenticated HTTP vulnerability
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in the Security component of Oracle Hyperion Financial Management, allowing an unauthenticated attacker to send HTTP requests that create, delete, or modify critical data. The flaw does not require authentication, so any user who can reach the HTTP interface can impact the confidentiality and integrity of the entire data set exposed by Hyperion.

Affected Systems

Oracle Hyperion Financial Management version 11.2.26.0.000 is the only affected release reported. No other versions are listed as vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 7.4 highlights serious confidentiality and integrity consequences, while an EPSS score below 1% indicates a low real‑world exploitation probability. The flaw is not catalogued in CISA’s KEV list. Still, the attack vector is over HTTP, so any network access to the Hyperion server opens a path for exploitation; this risk is amplified in environments lacking proper network segmentation.

Generated by OpenCVE AI on September 21, 2026 at 03:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply to a non‑vulnerable Hyperion Financial Management version
  • Restrict inbound HTTP traffic to known, trusted hosts or enforce firewall rules to block unauthorized access
  • Enable auditing and monitor Hyperion logs for unauthorized create, delete, or modify operations

Generated by OpenCVE AI on September 21, 2026 at 03:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Manipulation in Oracle Hyperion Financial Management

Mon, 21 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-Based Data Manipulation in Oracle Hyperion Financial Management
Weaknesses CWE-287
CWE-862

Mon, 21 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-Based Data Manipulation in Oracle Hyperion Financial Management
Weaknesses CWE-287
CWE-862

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit in Oracle Hyperion Financial Management Allows Data Modification
Weaknesses CWE-284

Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit in Oracle Hyperion Financial Management Allows Data Modification
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-20T23:53:13.090Z

Reserved: 2026-09-08T21:49:12.402Z

Link: CVE-2026-87198

cve-icon Vulnrichment

Updated: 2026-09-20T23:45:25.527Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:07.887

Modified: 2026-09-21T12:04:38.357

Link: CVE-2026-87198

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:45:08Z

Weaknesses