CVE-2026-87176
moderateUnauthenticated Data Access Flaw in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87176 is a critical (CVSS 9.1) flaw in the Security component of Oracle Hyperion Financial Management, the on-premises financial consolidation and close application used by enterprise finance organizations. It is triggered by an unauthenticated remote attacker who has network access to the server via TCP, requiring no privileges, credentials, or user interaction. A successful attack lets the attacker read, create, delete, or modify critical data — up to all data accessible to the Hyperion Financial Management environment — meaning an intruder could tamper with or exfiltrate financial consolidation and reporting data. Only version 11.2.26.0.000 is listed as affected. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported, but the low attack complexity and lack of authentication make it high priority to patch.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87176 and move off 11.2.26.0.000 to the latest patched 11.2.x release. Until patched, restrict TCP access to Hyperion Financial Management services to trusted VPN/administrative networks via firewall rules and segment the EPM tier from general user networks. Review audit logs for unexplained data creation, deletion, or modification in HFM applications and rotate service account credentials as a precaution.
| Oracle Hyperion Financial Management (component: Security) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.