ZeroHour

CVE-2026-87171

moderate

Unauthenticated Data Access Flaw in Oracle Hyperion Financial Management Security Component

CVSS 3.1
8.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87171 is a difficult-to-exploit, unauthenticated vulnerability in the Security component of Oracle Hyperion Financial Management (HFM) 11.2.26.0.000, reachable by a remote attacker over HTTPS with no privileges or user interaction. Successful exploitation lets the attacker create, delete, or modify critical data — or gain read access to all data accessible through HFM — and because the vulnerability changes scope, successful attacks may also significantly impact products beyond HFM itself. Organizations running the affected on-premises release are exposed wherever the HFM web tier is network-reachable, though exploitation requires overcoming high attack complexity and no public proof-of-concept or in-the-wild exploitation is known. The flaw carries a CVSS 3.1 base score of 8.7 (high), driven by full confidentiality and integrity impact with no availability impact.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87171 and confirm the fixed 11.2.26.x build in the corresponding Oracle advisory, as no fixed version is listed here. Restrict HTTPS access to HFM to VPN or internal networks and enforce authentication/MFA at the reverse proxy, since the flaw requires no credentials. Review HFM application and security logs for unexpected unauthenticated requests and any unauthorized creation, deletion, or modification of financial data, and check adjacent Hyperion products for follow-on impact given the scope change.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)
Estimated exposure
moderate≈1,000–5,000 internet-exposed HFM servers, plus a few thousand enterprise deployments worldwide (estimate) — HFM is licensed on-premises enterprise financial consolidation software deployed mainly by large finance organizations, and public internet scans typically surface only low thousands of exposed Oracle Hyperion/EPM HTTPS endpoints, with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.