Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Application Compromise
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an easily exploitable flaw in the security component of Oracle Hyperion Financial Management that allows a low‑privileged attacker with network access over HTTP to compromise the application. Successful exploitation can lead to a full takeover of the Hyperion system, affecting confidentiality, integrity and availability as indicated by the CVSS 3.1 score.

Affected Systems

The affected version is 11.2.26.0.000 of Oracle Hyperion Financial Management, a product of Oracle Corporation. Any installations of that specific version are vulnerable, with no other versions or variants listed.

Risk and Exploitability

The CVSS base score of 8.8 indicates a high severity. The EPSS score indicates a very low probability of exploitation, less than 1%, and the vulnerability is not listed in CISA KEV. The attack vector is remote over HTTP, requiring low privileges but no user interaction, which makes the risk significant for exposed systems.

Generated by OpenCVE AI on September 20, 2026 at 05:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched version of Oracle Hyperion Financial Management that resolves the security flaw as announced in the Oracle security advisory.
  • Apply the Oracle security patch for CVE-2026-87224 following the instructions in the referenced Oracle alert.
  • Restrict HTTP access to the Hyperion application to trusted networks and enforce strict authentication controls to reduce exposure.

Generated by OpenCVE AI on September 20, 2026 at 05:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Exploit Allowing Full Takeover of Oracle Hyperion Financial Management

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Remote HTTP Access Control Bypass in Oracle Hyperion Financial Management
Weaknesses CWE-284
CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Remote HTTP Access Control Bypass in Oracle Hyperion Financial Management
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:18.330Z

Reserved: 2026-09-08T21:49:12.404Z

Link: CVE-2026-87224

cve-icon Vulnrichment

Updated: 2026-09-17T12:56:31.955Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:10.737

Modified: 2026-09-22T17:17:02.350

Link: CVE-2026-87224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:45:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management