Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch Now
AI Analysis

Impact

The vulnerability in Oracle Hyperion Financial Management 11.2.26.0.000 allows an unauthenticated attacker to gain unauthorized access to critical financial data over HTTP. Based on the description, the flaw appears to be an authentication bypass leading to broken access control, which permits reading, updating, inserting, or deleting data that should be protected. The impact includes loss of confidentiality and limited integrity, enabling the attacker to alter or leak sensitive information.

Affected Systems

Oracle Hyperion Financial Management version 11.2.26.0.000. The product is deployed on Oracle Hyperion platforms and is vulnerable via its security component exposed over HTTP.

Risk and Exploitability

The CVSS v3.1 base score of 8.2 indicates a high confidentiality impact with low integrity loss. The EPSS score of < 1% reflects a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw using only network access to the HTTP interface; no credentials or user interaction is required, making the threat vector widely accessible to any network user.

Generated by OpenCVE AI on September 20, 2026 at 05:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s security patch for Hyperion Financial Management 11.2.26.0.000 as detailed in the Oracle security alert.
  • Limit exposure of the web application by placing it behind a firewall or VPN and restricting HTTP access to trusted IP addresses.
  • Disable or harden exposed endpoints to enforce authentication and authorization controls, ensuring that only authorized users can read or modify sensitive data.

Generated by OpenCVE AI on September 20, 2026 at 05:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Breach in Oracle Hyperion Financial Management

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Access in Oracle Hyperion Financial Management
Weaknesses CWE-285 CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Access in Oracle Hyperion Financial Management
Weaknesses CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:34:12.847Z

Reserved: 2026-09-08T21:49:12.405Z

Link: CVE-2026-87228

cve-icon Vulnrichment

Updated: 2026-09-18T13:58:21.007Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:11.170

Modified: 2026-09-21T12:09:18.073

Link: CVE-2026-87228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:45:16Z

Weaknesses