CVE-2026-87177
moderateLow-Privilege Data Access Flaw in Oracle Hyperion Financial Management Security Component
A high-severity (CVSS 8.5) vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, and because the scope changes, successful attacks may significantly impact products beyond Hyperion Financial Management itself. Exploitation can yield unauthorized access to critical data or complete access to all Hyperion Financial Management accessible data, plus unauthorized update, insert, or delete access to some of that data, with high confidentiality and low integrity impact and no availability impact. Organizations running the affected on-premises release are at risk, particularly where HFM web endpoints are reachable by broad internal user populations or exposed to the internet. No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation status is currently unknown/none known.
What to do: Apply the Oracle Critical Patch Update that remediates this flaw to move off Hyperion Financial Management 11.2.26.0.000. Restrict network access to HFM HTTP endpoints via firewalls and reverse proxies so only necessary finance users and systems can reach them, and enforce least-privilege account roles. Review HFM audit logs for anomalous data reads or modifications by low-privileged accounts and rotate credentials for accounts with HFM access.
| Oracle Hyperion Financial Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.