ZeroHour

CVE-2026-87181

niche

Low-Privilege Takeover Flaw in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87181 is a vulnerability in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. A low-privileged authenticated attacker with network access via HTTP can exploit it easily to fully compromise the application, impacting confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). Successful exploitation results in a complete takeover of the Hyperion Financial Management environment, which typically holds an organization's consolidated financial reporting data. The flaw is limited to the specific affected version, and organizations running older or patched releases outside that version string should verify their exact build. No public proof-of-concept is known and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87181 to any Hyperion Financial Management 11.2.26.0.000 deployment as soon as it is available, since only that version is listed as affected. Restrict HTTP access to the HFM web tier so that only authenticated finance users and trusted networks can reach it, and enforce least-privilege on all HFM accounts. Review logs for anomalous activity by low-privileged accounts, since successful exploitation leads to full application takeover.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
nichelikely low thousands of on-premises HFM deployments at large enterprises, with a smaller subset internet-exposed — Hyperion Financial Management is on-premises enterprise financial consolidation software deployed primarily at large corporations, and public internet scans typically show only a few hundred to low thousands of Hyperion-family endpoints…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.