Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote data modification without authentication
Action: Immediate Patch
AI Analysis

Impact

Oracle Hyperion Financial Management 11.2.26.0.000 contains a flaw in its security component that permits an attacker to perform a remote attack via HTTP with no authentication. The vulnerability allows the attacker to create, delete, or modify critical system data, or gain access to all data available within Oracle Hyperion Financial Management, thereby impacting confidentiality and integrity.

Affected Systems

The affected system is Oracle Hyperion Financial Management version 11.2.26.0.000.

Risk and Exploitability

The CVSS 3.1 base score is 9.1, indicating high severity. The EPSS score is less than 1%, which suggests that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated network request over HTTP targeting the application’s exposed endpoints. Successful exploitation would allow an attacker to modify or delete financial data without raising an immediate alarm.

Generated by OpenCVE AI on September 18, 2026 at 14:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any patched or updated version of Oracle Hyperion Financial Management released by Oracle.
  • If a patch is not yet available, restrict network access to the application by placing it behind a firewall and allowing only trusted IP ranges to reach its HTTP ports.
  • Ensure that all users have credentials with least privilege and enable multi‑factor authentication for any administrative access.

Generated by OpenCVE AI on September 18, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Access Enables Unauthorized Data Modification in Oracle Hyperion Financial Management

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:40.382Z

Reserved: 2026-09-08T21:49:12.404Z

Link: CVE-2026-87217

cve-icon Vulnrichment

Updated: 2026-09-15T22:46:57.191Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:09.983

Modified: 2026-09-21T12:44:31.277

Link: CVE-2026-87217

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:15:09Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function