Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Integrity Compromise
Action: Apply Patch
AI Analysis

Impact

A vulnerability in Oracle Hyperion Financial Management allows an attacker without authentication to create, delete, or modify critical data through network access via SSH. This flaw can lead to unauthorized changes to all data exposed by the application, severely compromising its confidentiality and integrity. The weakness is based on improper access control that enables unauthenticated data manipulation.

Affected Systems

The affected product is Oracle Hyperion Financial Management version 11.2.26.0.000, as supplied by Oracle Corporation. Only this specific release is known to be vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 7.4 indicates significant potential for data integrity impact, though the availability impact remains minimal. The EPSS score of less than 1% suggests exploitation is unlikely at present, and the vulnerability is not listed in CISA KEV. An attacker would need network-level access and the ability to establish an SSH session, after which the flaw permits unauthorized data manipulation. No known public exploit or mitigation is documented beyond the vendor advisory.

Generated by OpenCVE AI on September 18, 2026 at 17:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the security patch or update released by Oracle for Hyperion Financial Management 11.2.26.0.000
  • Restrict SSH access by limiting connections to trusted IP ranges and require multi‑factor authentication
  • Enable detailed logging of account creation, deletion, and critical data modifications, and regularly review logs for suspicious activity

Generated by OpenCVE AI on September 18, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Unauthenticated SSH Access in Oracle Hyperion Financial Management

Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Unauthenticated SSH Access in Oracle Hyperion Financial Management
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T14:47:51.039Z

Reserved: 2026-09-08T21:49:12.405Z

Link: CVE-2026-87235

cve-icon Vulnrichment

Updated: 2026-09-18T13:47:40.607Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:12.097

Modified: 2026-09-21T14:25:09.050

Link: CVE-2026-87235

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T17:30:11Z

Weaknesses