CVE-2026-87175
nicheUnauthenticated Data Access Flaw in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87175 is a critical (CVSS 9.1) vulnerability in the Security component of Oracle Hyperion Financial Management, affecting the supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker who has network access to the HFM server over TCP, requiring no privileges or user interaction. A successful attack allows the attacker to gain unauthorized creation, deletion, or modification access to critical data — or all data accessible to Oracle Hyperion Financial Management — as well as unauthorized read access to that data, with high confidentiality and integrity impact (availability is not affected). Organizations running HFM 11.2.26.0.000 for financial consolidation and close processes are affected, particularly if the service is reachable from untrusted network segments. No public proof of concept is known, the flaw is not in the CISA Known Exploited Vulnerabilities catalog, and there is no indication of in-the-wild exploitation to date.
What to do: Apply the fix Oracle ships in the Critical Patch Update that covers CVE-2026-87175 for Hyperion Financial Management 11.2.26, and verify you are not still running 11.2.26.0.000. Until patched, restrict TCP access to HFM application and service ports to trusted internal networks, management subnets, or VPN clients, and block exposure at perimeter firewalls or reverse proxies. Review HFM audit and application logs for unexpected data creation, modification, or deletion and for anomalous unauthenticated requests.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.