ZeroHour

CVE-2026-87170

moderate

Unauthenticated Critical Data Access in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-87170 is a critical (CVSS 3.1: 9.1) vulnerability in the Security component of Oracle Hyperion Financial Management (HFM), affecting supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack allows the attacker to create, delete, or modify critical data — or all data accessible to HFM — as well as read critical data or gain complete access to all HFM-accessible data; availability is not impacted per the CVSS vector (C:H/I:H/A:N). Organizations running the affected HFM release with the service reachable over a network are at risk, especially if the web tier is internet-facing. There is no known public proof of concept and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-87170 to any Hyperion Financial Management 11.2.26.0.000 deployment as soon as it is available. Until patched, restrict HTTP access to the HFM web tier to trusted internal networks or VPN, and place it behind authentication proxies or WAF rules where feasible. Review HFM audit and access logs for unauthenticated requests to the Security component to rule out prior exploitation.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
moderate≈ a few thousand installations globally (large-enterprise finance/consolidation deployments, with only a subset internet-exposed) — Oracle Hyperion Financial Management is on-premises enterprise EPM software used mainly by large corporate finance organizations, which typically number in the low thousands of deployments worldwide and are usually internal-facing rather…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.