CVE-2026-87181
nicheLow-Privilege Takeover Flaw in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87181 is a vulnerability in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. A low-privileged authenticated attacker with network access via HTTP can exploit it easily to fully compromise the application, impacting confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). Successful exploitation results in a complete takeover of the Hyperion Financial Management environment, which typically holds an organization's consolidated financial reporting data. The flaw is limited to the specific affected version, and organizations running older or patched releases outside that version string should verify their exact build. No public proof-of-concept is known and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87181 to any Hyperion Financial Management 11.2.26.0.000 deployment as soon as it is available, since only that version is listed as affected. Restrict HTTP access to the HFM web tier so that only authenticated finance users and trusted networks can reach it, and enforce least-privilege on all HFM accounts. Review logs for anomalous activity by low-privileged accounts, since successful exploitation leads to full application takeover.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.