ZeroHour

CVE-2026-87175

niche

Unauthenticated Data Access Flaw in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-87175 is a critical (CVSS 9.1) vulnerability in the Security component of Oracle Hyperion Financial Management, affecting the supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker who has network access to the HFM server over TCP, requiring no privileges or user interaction. A successful attack allows the attacker to gain unauthorized creation, deletion, or modification access to critical data — or all data accessible to Oracle Hyperion Financial Management — as well as unauthorized read access to that data, with high confidentiality and integrity impact (availability is not affected). Organizations running HFM 11.2.26.0.000 for financial consolidation and close processes are affected, particularly if the service is reachable from untrusted network segments. No public proof of concept is known, the flaw is not in the CISA Known Exploited Vulnerabilities catalog, and there is no indication of in-the-wild exploitation to date.

What to do: Apply the fix Oracle ships in the Critical Patch Update that covers CVE-2026-87175 for Hyperion Financial Management 11.2.26, and verify you are not still running 11.2.26.0.000. Until patched, restrict TCP access to HFM application and service ports to trusted internal networks, management subnets, or VPN clients, and block exposure at perimeter firewalls or reverse proxies. Review HFM audit and application logs for unexpected data creation, modification, or deletion and for anomalous unauthenticated requests.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
nichelikely low thousands of enterprise deployments (order of 1,000–10,000 installations), mostly on internal networks — Oracle Hyperion Financial Management is licensed, on-premises financial consolidation software used mainly by corporate finance departments of large and mid-sized enterprises, with no public active-install or internet-scan counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.