Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access
Action: Patch ASAP
AI Analysis

Impact

The vulnerability resides in the Security component of Oracle Hyperion Financial Management and allows an unauthenticated attacker to compromise the system via HTTP. Successful exploitation can lead to unauthorized access to critical data or complete data exposed by the application, resulting in a significant confidentiality impact.

Affected Systems

The affected product is Oracle Hyperion Financial Management version 11.2.26.0.000.

Risk and Exploitability

The CVSS 3.1 score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based HTTP request from an unauthenticated attacker, implying remote exploitation without prior authentication. Because no patch is currently listed, the risk persists for systems exposed to the internet, necessitating immediate mitigation and monitoring.

Generated by OpenCVE AI on September 18, 2026 at 15:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a non‑vulnerable version of Oracle Hyperion Financial Management when one becomes available.
  • Restrict HTTP access to Hyperion interfaces to trusted networks or VPNs and enforce network segmentation to limit exposure.
  • Configure firewall rules to block unnecessary inbound traffic on the HTTP ports used by Hyperion.
  • Enable audit logging and regularly review logs for anomalous access attempts or unauthorized data retrieval.

Generated by OpenCVE AI on September 18, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploit Allows Unauthenticated Data Access in Oracle Hyperion Financial Management
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T17:43:54.028Z

Reserved: 2026-09-08T21:49:12.403Z

Link: CVE-2026-87211

cve-icon Vulnrichment

Updated: 2026-09-18T17:43:31.090Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:09.337

Modified: 2026-09-21T11:58:21.030

Link: CVE-2026-87211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T15:30:11Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control