ZeroHour

CVE-2026-87182

niche

Privilege Escalation in Oracle Hyperion Financial Management Security Component

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

A vulnerability in the Security component of Oracle Hyperion Financial Management (HFM) version 11.2.26.0.000 lets a low-privileged attacker who already has logon access to the infrastructure hosting HFM fully compromise the application. The flaw is rated CVSS 3.1 8.8 with a scope change (S:C), meaning successful attacks can also significantly impact additional products running on the same infrastructure beyond HFM itself. Exploitation is described as easy and results in high impacts to confidentiality, integrity, and availability, up to complete takeover of Oracle Hyperion Financial Management. Only the supported version 11.2.26.0.000 is listed as affected. No public proof of concept exists, the issue is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild is known.

What to do: Apply the Oracle Critical Patch Update that addresses this flaw and upgrade from HFM 11.2.26.0.000 to the patched release. Because exploitation only requires a low-privileged local account, tightly restrict and audit OS/service accounts on Hyperion hosts and enforce least privilege. Given the scope-change impact, monitor shared Hyperion infrastructure for privilege escalation or unexpected activity affecting co-resident products.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
nichelikely low thousands of on-premises enterprise deployments worldwide (no public install counts) — Oracle Hyperion Financial Management is on-premises enterprise performance management software used mainly by mid-size and large finance organizations, a customer population typically estimated in the low thousands, and Oracle publishes no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.