Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and access
Action: Patch
AI Analysis

Impact

The vulnerability exists in the Security component of Oracle Hyperion Financial Management 11.2.26.0.000, representing a broken access control weakness (CWE-284). An attacker who can communicate over the physical network segment attached to the hardware where the application runs can exploit the flaw without authentication or privileges. Successful exploitation permits the attacker to create, delete, or alter critical data, and it may provide full access to all data the application can reach. This results in significant confidentiality and integrity damage to the system's data, and the scope change indicates that the compromise could extend to other affected products.

Affected Systems

Only Oracle Hyperion Financial Management 11.2.26.0.000 is listed as affected. The vendor is Oracle Corporation, and the product affected is Hyperion Financial Management. Users deploying this specific release should assess whether they are using the affected version and plan remediation accordingly.

Risk and Exploitability

The CVSS v3.1 base score of 8.0 signals a high severity vulnerability. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The required attack vector is local: the attacker must be able to reach the physical communication segment attached to the Hyperion servers, with no privilege elevation or user interaction needed. Once accessed, the scope change permits broader impact across the environment.

Generated by OpenCVE AI on September 18, 2026 at 17:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s official patch or upgrade to a fixed version of Hyperion Financial Management
  • Restrict physical access to the communication segment connecting to the Hyperion servers, using network segmentation and access controls
  • Monitor database and application logs for unauthorized data modifications or access attempts

Generated by OpenCVE AI on September 18, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation in Oracle Hyperion Financial Management 11.2.26

Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation in Oracle Hyperion Financial Management 11.2.26
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T14:47:15.762Z

Reserved: 2026-09-08T21:49:12.406Z

Link: CVE-2026-87243

cve-icon Vulnrichment

Updated: 2026-09-18T13:47:48.981Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:13.033

Modified: 2026-09-21T14:42:37.393

Link: CVE-2026-87243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T17:45:11Z

Weaknesses