Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote unauthorized data access and partial denial of service
Action: Apply Patch
AI Analysis

Impact

A vulnerability in Oracle Hyperion Financial Management allows a low‑privileged attacker with network access via HTTP to bypass access controls, resulting in unauthorized access to critical data or even full access to all data managed by the application, along with the potential to cause a partial denial of service. The flaw relies on improper authorization checks in a security component, providing high confidentiality impact with a moderate availability impact as indicated by the CVSS score of 7.1.

Affected Systems

Oracle Hyperion Financial Management version 11.2.26.0.000 is affected. The vulnerability is present in the security component of this product and affects installations that expose the HTTP interface to the network.

Risk and Exploitability

The CVSS vector:L/UI:N) reflects a network vulnerability that is easily exploitable for a low‑privileged attacker. The EPSS score of less than 1 % suggests that, while the vulnerability is present, exploitation activity may be limited. The vulnerability is not listed in the CISA KEV catalog. An attacker could leverage the exposed HTTP service to exploit the bug, gain unauthorized access, and possibly disrupt services. Monitoring for suspicious HTTP traffic and restricting access are advised.

Generated by OpenCVE AI on September 18, 2026 at 16:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or upgrade to a newer version of Oracle Hyperion Financial Management that fixes the access‑control flaw.
  • Restrict direct HTTP access to Hyperion to trusted internal networks or protected gateways, and enforce network segmentation.
  • Configure and enforce stricter authenticationfactor authentication or role‑based access control, to reduce the risk of unauthorized access.

Generated by OpenCVE AI on September 18, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Hyperion Financial Management 11.2.26.0.000 Allows Low‑Privilege Attacker Access

Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Hyperion Financial Management 11.2.26.0.000 Allows Low‑Privilege Attacker Access
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T14:47:40.573Z

Reserved: 2026-09-08T21:49:12.405Z

Link: CVE-2026-87236

cve-icon Vulnrichment

Updated: 2026-09-18T13:49:08.538Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:12.217

Modified: 2026-09-21T14:25:36.727

Link: CVE-2026-87236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T16:45:11Z

Weaknesses