Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L).
Published: 2026-09-15
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Partial Denial of Service
Action: Patch Immediately
AI Analysis

Impact

A vulnerability in the Security component of Oracle Hyperion Financial Management allows a remote attacker with high privileges and network access via HTTP to compromise the system. The flaw can lead to unauthorized access to critical or all accessible data, and allows an attacker to cause a partial denial of service. The weakness is a privilege escalation or improper access control flaw, reflected in the CVSS 3.1 vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L, giving confidentiality high impact and availability low impact.

Affected Systems

Affected systems are Oracle Hyperion Financial Management version 11.2.26.0.000, delivered by Oracle Corporation. The vulnerability applies only to this version unless newer editions include the same issue, which is not documented in the advisory.

Risk and Exploitability

The CVSS base score of 7.6 indicates a high‑severity vulnerability. The EPSS score of less than 1 % shows a very low probability of exploitation in the current pool of active threats, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the attack vector is network accessible HTTP traffic, a high‑privileged attacker can exploit the flaw with low complexity and no user interaction, potentially gaining full data access or a partial denial of service. The scope change increases the attack surface, giving the attacker broader impact beyond the originally confined scope.

Generated by OpenCVE AI on September 21, 2026 at 18:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available Oracle patch or update for Oracle Hyperion Financial Management 11.2.26.0.000.
  • Restrict network exposure of the Hyperion service by allowing only trusted IP addresses or placing the application behind a VPN or firewall.
  • Implement strict access control and conduct a least‑privilege review of accounts that interact with the Hyperion system.
  • Monitor system logs for anomalous activity and enforce alerting on unauthorized data access attempts.

Generated by OpenCVE AI on September 21, 2026 at 18:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title High Privilege Visibility and Denial of Service in Oracle Hyperion Financial Management 11.2.26.0.000

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploit Grants Full Access to Oracle Hyperion Financial Management
Weaknesses CWE-200
CWE-269

Mon, 21 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploit Grants Full Access to Oracle Hyperion Financial Management
Weaknesses CWE-200
CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:33:42.468Z

Reserved: 2026-09-08T21:49:12.405Z

Link: CVE-2026-87233

cve-icon Vulnrichment

Updated: 2026-09-18T13:49:06.338Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:11.857

Modified: 2026-09-21T14:51:21.330

Link: CVE-2026-87233

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T18:45:18Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-284

    Improper Access Control