Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Application Compromise
Action: Assess Impact
AI Analysis

Impact

A weakness in the security component of Oracle Hyperion Financial Management allows a low‑privileged attacker with network access over HTTP to compromise the application. If successfully exploited, the attacker can take full control, leading to loss of confidentiality, integrity and availability of the financial management system.

Affected Systems

Oracle Hyperion Financial Management version 11.2.26.0.000 supplied by Oracle Corporation.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates high severity with full impact on confidentiality, integrity and availability. The EPSS score is below 1 %, implying a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can target the publicly reachable HTTP interface, crafting requests that trigger the compromise of the application.

Generated by OpenCVE AI on September 20, 2026 at 05:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Consult Oracle’s security advisory at https://www.oracle.com/security-alerts/cspusep2026.html for update procedures and any available mitigations.
  • Limit HTTP access to Hyperion by applying network segmentation, firewall rules or VPN restrictions so only trusted hosts can reach the affected service.
  • Enforce least‑privilege on all accounts used to access Hyperion, disabling unused administrative functions and reviewing role assignments.
  • Enable logging and monitoring of HTTP traffic to detect anomalous activity that could indicate exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 05:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Application Takeover via HTTP in Oracle Hyperion Financial Management 11.2.26.0.000

Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Attack Compromise of Oracle Hyperion Financial Management 11.2.26
Weaknesses CWE-284
CWE-862

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Attack Compromise of Oracle Hyperion Financial Management 11.2.26
Weaknesses CWE-284
CWE-862

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:16.784Z

Reserved: 2026-09-08T21:49:12.406Z

Link: CVE-2026-87247

cve-icon Vulnrichment

Updated: 2026-09-17T12:55:51.255Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:13.500

Modified: 2026-09-21T13:07:23.873

Link: CVE-2026-87247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:30:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management