Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification and Access
Action: Patch Immediately
AI Analysis

Impact

The vulnerability in Oracle Hyperion Financial Management allows an attacker with low privileges and network access via HTTP to perform unauthorized creation, deletion or modification of data, and potentially gain complete access to all data managed by the application. This flaw demonstrates a severe confidentiality and integrity impact, as indicated by the CVSS vector of high impact on confidentiality and integrity while availability remains unaffected. The issue is rooted in improper privilege or access control, permitting low‑privileged users to act with higher levels of authority than intended.

Affected Systems

Oracle Corporation’s Hyperion Financial Management product, version 11.2.26.0.000, is the only affected release. This version is explicitly identified in the vendor’s security alert and CPE string.

Risk and Exploitability

With a CVSS score of 8.1 the vulnerability is considered high severity. The EPSS score is less than 1 %, indicating a currently low but non‑zero probability of exploitation. The issue is not listed in CISA’s KEV catalog, which suggests it is not widely exploited at this time. Attackers would need to target the application over an unsecured HTTP connection and have a low‑privilege account or credential; from there they can exploit improper access control to elevate privileges and compromise data. Combinations of network access, application flaws and inadequate privileges make the context of exploitation plausible, yet the likelihood remains modest according to EPSS.

Generated by OpenCVE AI on September 18, 2026 at 16:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch for version 11.2.26.0.000 immediately
  • Restrict network traffic to the Oracle Hyperion server using a firewall or VPN so that only trusted hosts can reach the HTTP endpoint
  • Enforce the principle of least privilege on all user accounts used to access the application

Generated by OpenCVE AI on September 18, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Account Over HTTP Enables Unauthorized Data Modification and Access in Oracle Hyperion Financial Management

Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Account Over HTTP Enables Unauthorized Data Modification and Access in Oracle Hyperion Financial Management
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T14:48:05.120Z

Reserved: 2026-09-08T21:49:12.405Z

Link: CVE-2026-87234

cve-icon Vulnrichment

Updated: 2026-09-18T13:47:37.811Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:11.970

Modified: 2026-09-21T14:20:42.783

Link: CVE-2026-87234

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T16:45:11Z

Weaknesses