ZeroHour

CVE-2026-87174

moderate

Unauthenticated Data Access Flaw in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87174 is a vulnerability in the Security component of Oracle Hyperion Financial Management (HFM), affecting supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker who has network access to the HFM server over TCP, with no user interaction or privileges required (CVSS 3.1 base score 8.2). A successful attack can result in unauthorized read access to critical data or complete access to all HFM-accessible data, as well as unauthorized update, insert, or delete access to some of that data; availability is not impacted. Organizations running the listed version of this on-premises enterprise financial close and consolidation application are affected. There is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported to date.

What to do: Apply the Oracle Critical Patch Update that remediates this issue to Hyperion Financial Management 11.2.26.0.000 as soon as it is available, since that supported version is the only one listed as affected. Until patched, restrict TCP connectivity to HFM and its Shared Services ports to trusted networks or VPN clients via firewall allow-listing, and enable logging. Review application and server logs for unauthenticated access patterns or unexpected data reads, inserts, updates, or deletes.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
moderate≈ a few thousand enterprise deployments worldwide; likely only hundreds to low thousands of internet-exposed HFM servers (estimate) — Oracle publishes no install counts, but Hyperion HFM is a niche on-premises EPM product purchased mainly by large finance organizations and typically deployed inside the corporate network behind firewalls or VPN, so public internet scans…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.