Oracle disclosed a maximum-severity flaw in the Security component of Oracle Hyperion Financial Management 11.2.26.0.000 that lets an unauthenticated remote attacker read and alter all data accessible to the product over HTTP, with a scored scope change that reaches past the vulnerable product itself.
What Is It
The vulnerability sits in the Security component of Oracle Hyperion Financial Management, part of the Oracle Hyperion product family. Oracle describes it as easily exploitable: an attacker with network access via HTTP and no credentials can compromise the application without any user interaction. Successful exploitation yields unauthorized creation, deletion, or modification of critical data, or all data accessible to Hyperion Financial Management, along with unauthorized read access up to complete access to that same data.
The CVSS 3.1 base score is 10.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. Confidentiality and integrity impacts are HIGH; availability impact is NONE. That last value is worth reading carefully alongside the impact description: the documented consequences are confidentiality and integrity outcomes against data, and Oracle's scoring does not claim the flaw can be used to halt or degrade the service itself. Deleting or corrupting consolidation data can of course leave the application unusable in practice, but that is a downstream effect of the integrity impact rather than a separately scored availability impact. The record was published 2026-09-15 with a status of "Received," sourced from Oracle's security alert channel.
Why It Matters
Two details drive the 10.0 score. First, exploitation requires nothing from the attacker but network reach; no privileges, no user interaction, low complexity. Second, the scope is CHANGED: Oracle explicitly notes that while the vulnerability resides in Hyperion Financial Management, attacks may significantly impact additional products. Oracle does not name those products or describe the mechanism, so the extent of any spillover is unspecified in the available data.
Hyperion Financial Management handles financial consolidation and reporting data, so the integrity half of this, unauthorized creation, deletion, or modification of critical records, carries consequences beyond data theft.
No CISA KEV entry accompanies this record, so there is no confirmation of active exploitation in the supplied data.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Hyperion Financial Management (component: Security)
- Affected supported version: 11.2.26.0.000
No CPE entries are present in the NVD record at this time.
Patch Status
Oracle's September 2026 security alert is the sole reference on this CVE and is the authoritative source for fix availability and applicable patches. Administrators running 11.2.26.0.000 should consult that advisory directly. The supplied data contains no vendor-specified required action deadline and no CISA-mandated remediation date.
Sources
- Oracle Security Alert (September 2026), https://www.oracle.com/security-alerts/cspusep2026.html
- NVD, CVE-2026-87230, https://nvd.nist.gov/vuln/detail/CVE-2026-87230