ZeroHour

CVE-2026-87172

niche

Critical Privilege Escalation to Full Takeover in Oracle Hyperion Financial Management

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

Oracle Hyperion Financial Management version 11.2.26.0.000 contains an easily exploitable flaw in its Security component, rated CVSS 3.1 9.9 (critical). A remote attacker holding only low-privileged (authenticated) access over HTTP can exploit the flaw to fully take over the Oracle Hyperion Financial Management application, with high impact to confidentiality, integrity, and availability. The CVSS scope-change metric (S:C) indicates successful attacks may also significantly impact additional products beyond Financial Management itself. Organizations running on-premises Oracle Hyperion/EPM deployments on the affected version are exposed wherever the HFM web tier is reachable by low-privileged users. No public proof-of-concept exists, the issue is not on CISA's KEV list, and no in-the-wild exploitation is currently known.

What to do: Apply the Oracle Critical Patch Update that remediates this vulnerability and move off version 11.2.26.0.000 to the latest available patch in the 11.2.x line. Until patched, restrict HTTP access to HFM web endpoints to trusted networks or VPN, audit and minimize low-privileged HFM accounts, and monitor for unexpected privilege changes or configuration modifications. Because the CVSS scope is 'changed,' also review and harden adjacent Hyperion/EPM components sharing infrastructure, trusts, or credentials with HFM.

Affected
Oracle Hyperion Financial Management11.2.26.0.000
Estimated exposure
nichelikely low thousands of enterprise deployments worldwide (order of 1,000-10,000 installations) — Oracle Hyperion Financial Management is an on-premises enterprise performance management product licensed to large finance organizations rather than a mass-market tool, so its install base is inherently limited and most instances are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.