Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Application Takeover
Action: Immediate Patch
AI Analysis

Impact

An exploitable flaw in the security component of Oracle Hyperion Financial Management allows a network attacker with high privileges to take full control of the system. Success can compromise confidentiality, integrity and availability of the application, potentially leading to a complete takeover of the affected instance. The weakness aligns with improper privilege management and unauthorized access controls.

Affected Systems

Oracle Hyperion Financial Management version 11.2.26.0.000 is affected. The vulnerability resides in the security component and may impact other Oracle Hyperion products because the attack escalates privileges and modifies application state.

Risk and Exploitability

The CVSS score of 9.1 points to a critical severity. The EPSS score of <1% suggests that while exploitation is not widespread, the vulnerability remains worth addressing promptly. The fact that it is not in the KEV catalog does not reduce the need for mitigation, as the potential for compromise is extreme and would likely affect any environment where the vulnerable product is deployed. The attack likely proceeds via network-based HTTP requests that exploit the flawed access control, requiring a high‑privilege attacker to gain control, and may also extend to additional products due to scope change.

Generated by OpenCVE AI on September 20, 2026 at 06:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle patch or upgrade to a version where the vulnerability is fixed
  • Restrict HTTP access to Oracle Hyperion Financial Management to trusted hosts or networks
  • Disable or remove unnecessary HTTP endpoints and enforce strict authentication on remaining ones

Generated by OpenCVE AI on September 20, 2026 at 06:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Takeover in Oracle Hyperion Financial Management

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title High Severity Remote Exploit for Oracle Hyperion Financial Management 11.2.26.0.000
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title High Severity Remote Exploit for Oracle Hyperion Financial Management 11.2.26.0.000
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:18.502Z

Reserved: 2026-09-08T21:49:12.404Z

Link: CVE-2026-87214

cve-icon Vulnrichment

Updated: 2026-09-17T12:56:35.186Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:09.660

Modified: 2026-09-21T12:45:29.183

Link: CVE-2026-87214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:15:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management