CVE-2026-87173
nicheUnauthenticated Data Access Flaw in Oracle Hyperion Financial Management 11.2.26
Oracle Hyperion Financial Management version 11.2.26.0.000 contains a critical vulnerability in its Security component that allows an unauthenticated attacker with network access via TCP to compromise the application (CVSS 3.1: 9.1). The flaw requires no privileges, no user interaction, and is rated as easily exploitable. A successful attack gives the attacker unauthorized ability to create, delete, or modify critical data — or all data accessible to Hyperion Financial Management — as well as unauthorized read access to critical data or complete read access to all accessible data. Availability is not impacted (A:N), so the risk centers on confidentiality and integrity of financial close, consolidation, and reporting data. Organizations running the affected on-premises version are exposed wherever the service is reachable over the network; no public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not on the CISA KEV list.
What to do: Apply the Oracle Critical Patch Update that remediates this flaw to move off affected version 11.2.26.0.000 as soon as it is available. Until patched, restrict TCP access to Hyperion Financial Management services at the firewall so only trusted internal clients and VPN users can reach them, and avoid any internet exposure. Review HFM audit logs for unexpected data creation, modification, or deletion and for access from unexplained sources.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.