CVE-2026-87174
moderateUnauthenticated Data Access Flaw in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87174 is a vulnerability in the Security component of Oracle Hyperion Financial Management (HFM), affecting supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker who has network access to the HFM server over TCP, with no user interaction or privileges required (CVSS 3.1 base score 8.2). A successful attack can result in unauthorized read access to critical data or complete access to all HFM-accessible data, as well as unauthorized update, insert, or delete access to some of that data; availability is not impacted. Organizations running the listed version of this on-premises enterprise financial close and consolidation application are affected. There is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported to date.
What to do: Apply the Oracle Critical Patch Update that remediates this issue to Hyperion Financial Management 11.2.26.0.000 as soon as it is available, since that supported version is the only one listed as affected. Until patched, restrict TCP connectivity to HFM and its Shared Services ports to trusted networks or VPN clients via firewall allow-listing, and enable logging. Review application and server logs for unauthenticated access patterns or unexpected data reads, inserts, updates, or deletes.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.