Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access
Action: Apply Update
AI Analysis

Impact

Oracle Hyperion Financial Management version 11.2.26.0.000 contains a flaw in its security component that allows an unauthenticated attacker to bypass authentication via HTTP. The weakness falls under CWE‑306 (Missing Authentication). Successful exploitation grants the attacker unauthorized access to critical application data, compromising confidentiality without affecting integrity or availability.

Affected Systems

Oracle Hyperion Financial Management, version 11.2.26.0.000, used by organizations managing financial data. The vulnerability is confined to this specific version of the product.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 reflects a medium‑to‑high severity focused on confidentiality impact. The EPSS score is below 1 %, indicating a low current exploitation probability, and the issue is not listed in CISA’s KEV catalog. Attackers can launch the exploit over plain HTTP with no credentials, making the attack path straightforward and potentially granting full data access.

Generated by OpenCVE AI on September 21, 2026 at 20:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available updates to Oracle Hyperion Financial Management 11.2.26.0.000 as per the Oracle security alert in the references.
  • Configure the application or network perimeter to block public HTTP access, allowing connections only from trusted IP ranges or VPN endpoints.
  • Update Hyperion’s web configuration to enforce authentication for all endpoints and enable HTTPS, reducing exposure to unauthenticated HTTP requests.

Generated by OpenCVE AI on September 21, 2026 at 20:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authentication Bypass in Oracle Hyperion Financial Management
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploit in Oracle Hyperion Financial Management
Weaknesses CWE-287

Mon, 21 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Sun, 20 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploit in Oracle Hyperion Financial Management
Weaknesses CWE-287

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploitation in Oracle Hyperion Financial Management 11.2.26.0.000
Weaknesses CWE-284

Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploitation in Oracle Hyperion Financial Management 11.2.26.0.000
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T19:34:25.899Z

Reserved: 2026-09-08T21:49:12.403Z

Link: CVE-2026-87205

cve-icon Vulnrichment

Updated: 2026-09-21T19:34:18.255Z

cve-icon NVD

Status : Modified

Published: 2026-09-15T20:19:08.663

Modified: 2026-09-21T20:17:39.090

Link: CVE-2026-87205

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T20:15:16Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function