ZeroHour

CVE-2026-87179

moderate

Privilege Escalation to Full Takeover in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87179 is a flaw in the Security component of Oracle Hyperion Financial Management (HFM) version 11.2.26.0.000 that allows a low-privileged, authenticated attacker with network access via HTTP to compromise the application. Exploitation is rated easy and requires only valid low-level credentials and reachability of the HFM web tier, with no user interaction needed. A successful attack can result in a complete takeover of Oracle Hyperion Financial Management, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). Organizations running the affected supported release 11.2.26.0.000 are exposed, especially where HFM endpoints are reachable beyond the internal finance network. No public proof-of-concept is known and the flaw is not on the CISA KEV catalog, so active exploitation has not been observed.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87179 to your 11.2.x environment as soon as it is released, treating 11.2.26.0.000 as unpatched until then. Restrict HTTP access to HFM to trusted internal networks or VPN, limit low-privileged account grants, and audit the Security component's logs and user role assignments for unauthorized privilege changes or anomalous account activity.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
moderate≈1,000–5,000 on-prem HFM deployments worldwide, only a small fraction internet-exposed — HFM is an on-premises enterprise financial consolidation/EPM product typically licensed by large finance organizations numbering in the low thousands globally, and public scan data consistently shows only a small number of internet-exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.