ZeroHour

CVE-2026-87178

moderate

High-Privilege SQL Data Compromise in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
8.7 high
EPSS
Published
()
Modified
AI analysis

Oracle Hyperion Financial Management version 11.2.26.0.000 contains a vulnerability in its Security component that is easily exploitable by a high-privileged attacker with network access via SQL. Successful exploitation allows the attacker to create, delete, or modify critical data — or all data accessible to Hyperion Financial Management — as well as gain unauthorized read access to that data, with confidentiality and integrity both highly impacted (CVSS 8.7). Because of a scope change, successful attacks on this flaw can also significantly impact additional products beyond Hyperion Financial Management itself. The affected population is organizations running the affected 11.2.26 release of this enterprise financial consolidation application, typically large finance departments with on-premises deployments. There is no known public proof of concept and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw and move off the affected 11.2.26.0.000 release to a patched version. Restrict SQL-level and network access to Hyperion Financial Management back-end databases to only trusted administrative accounts and hosts, apply least-privilege to database roles, and monitor for unexpected data modification or privilege escalation activity by high-privileged accounts.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
moderate≈ low thousands of on-premises enterprise installations worldwide — Oracle Hyperion Financial Management is enterprise EPM software deployed mainly inside large corporate finance organizations, typically not internet-facing, and its installed base is estimated in the low thousands of deployments globally;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.