CVE-2026-87179
moderatePrivilege Escalation to Full Takeover in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87179 is a flaw in the Security component of Oracle Hyperion Financial Management (HFM) version 11.2.26.0.000 that allows a low-privileged, authenticated attacker with network access via HTTP to compromise the application. Exploitation is rated easy and requires only valid low-level credentials and reachability of the HFM web tier, with no user interaction needed. A successful attack can result in a complete takeover of Oracle Hyperion Financial Management, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). Organizations running the affected supported release 11.2.26.0.000 are exposed, especially where HFM endpoints are reachable beyond the internal finance network. No public proof-of-concept is known and the flaw is not on the CISA KEV catalog, so active exploitation has not been observed.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87179 to your 11.2.x environment as soon as it is released, treating 11.2.26.0.000 as unpatched until then. Restrict HTTP access to HFM to trusted internal networks or VPN, limit low-privileged account grants, and audit the Security component's logs and user role assignments for unauthorized privilege changes or anomalous account activity.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.