CVE-2026-87170
moderateUnauthenticated Critical Data Access in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87170 is a critical (CVSS 3.1: 9.1) vulnerability in the Security component of Oracle Hyperion Financial Management (HFM), affecting supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack allows the attacker to create, delete, or modify critical data — or all data accessible to HFM — as well as read critical data or gain complete access to all HFM-accessible data; availability is not impacted per the CVSS vector (C:H/I:H/A:N). Organizations running the affected HFM release with the service reachable over a network are at risk, especially if the web tier is internet-facing. There is no known public proof of concept and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-87170 to any Hyperion Financial Management 11.2.26.0.000 deployment as soon as it is available. Until patched, restrict HTTP access to the HFM web tier to trusted internal networks or VPN, and place it behind authentication proxies or WAF rules where feasible. Review HFM audit and access logs for unauthenticated requests to the Security component to rule out prior exploitation.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.