ZeroHour

CVE-2026-87173

niche

Unauthenticated Data Access Flaw in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

Oracle Hyperion Financial Management version 11.2.26.0.000 contains a critical vulnerability in its Security component that allows an unauthenticated attacker with network access via TCP to compromise the application (CVSS 3.1: 9.1). The flaw requires no privileges, no user interaction, and is rated as easily exploitable. A successful attack gives the attacker unauthorized ability to create, delete, or modify critical data — or all data accessible to Hyperion Financial Management — as well as unauthorized read access to critical data or complete read access to all accessible data. Availability is not impacted (A:N), so the risk centers on confidentiality and integrity of financial close, consolidation, and reporting data. Organizations running the affected on-premises version are exposed wherever the service is reachable over the network; no public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not on the CISA KEV list.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw to move off affected version 11.2.26.0.000 as soon as it is available. Until patched, restrict TCP access to Hyperion Financial Management services at the firewall so only trusted internal clients and VPN users can reach them, and avoid any internet exposure. Review HFM audit logs for unexpected data creation, modification, or deletion and for access from unexplained sources.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
nichelow thousands of enterprise installations globally, with likely only hundreds internet-exposed — Hyperion Financial Management is on-premises enterprise financial consolidation software deployed primarily at large organizations, and public internet scans typically show only a small number of exposed Hyperion endpoints since these…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.