Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Takeover
Action: Patch promptly
AI Analysis

Impact

A vulnerability in the security component of Oracle Hyperion Financial Management allows a low‑privileged attacker with network access via HTTP to compromise the system. When exploited, the attacker can take full control of the application, resulting in loss of confidentiality, integrity, and availability for all data managed by the platform. The weakness is described as difficult to exploit, yet the CVSS vector indicates the potential for a complete takeover.

Affected Systems

The affected product is Oracle Hyperion Financial Management, version 11.2.26.0.000, provided by Oracle Corporation.

Risk and Exploitability

The vulnerability has a CVSS 3.1 base score of 7.5, indicating high severity, but the EPSS score is less than 1% which suggests that it is unlikely to be widely exploited at this time. It is not listed in the CISA KEV catalog. The described attack vector requires network access over HTTP and a low‑privileged account; no user interaction is needed, so the risk from reconnaissance and credentialed access is significant if the system is exposed to untrusted networks.

Generated by OpenCVE AI on September 17, 2026 at 23:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s latest security patch for Oracle Hyperion Financial Management 11.2.26.0.000 as soon as it becomes available.
  • Restrict external HTTP access to the Hyperion instance by configuring firewalls or access‑control lists to allow only trusted IP addresses.
  • Enable comprehensive auditing and monitoring on the Hyperion server and review logs for suspicious remote access attempts related to the security component.

Generated by OpenCVE AI on September 17, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Low Privileged HTTP Access Allows Takeover of Oracle Hyperion Financial Management

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Low Privileged HTTP Access Allows Takeover of Oracle Hyperion Financial Management
Weaknesses CWE-284

Wed, 16 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle Corporation
Oracle Corporation oracle Hyperion Financial Management
Vendors & Products Oracle Corporation
Oracle Corporation oracle Hyperion Financial Management

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
Oracle Corporation Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:17.691Z

Reserved: 2026-09-08T21:49:12.405Z

Link: CVE-2026-87237

cve-icon Vulnrichment

Updated: 2026-09-17T12:56:17.667Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:12.343

Modified: 2026-09-21T12:00:18.980

Link: CVE-2026-87237

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control