ZeroHour

CVE-2026-87183

niche

High-Privilege Local Takeover Flaw in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87183 is a vulnerability in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. It is easily exploitable by an attacker who already holds high privileges and can log on to the infrastructure where HFM executes, but a successful attack also requires human interaction from someone other than the attacker, implying a social-engineering or user-assisted component. If exploited, the attacker can fully compromise Oracle Hyperion Financial Management (takeover with high confidentiality, integrity, and availability impact), and because of a scope change, successful attacks may also significantly impact additional products beyond HFM. The affected population is limited to organizations running the on-premises HFM 11.2.26.0.000 release. The flaw is not listed in CISA's KEV catalog and no public proof-of-concept is known, so there is no evidence of active exploitation.

What to do: Apply the Oracle Critical Patch Update that remediates this issue in Hyperion Financial Management 11.2.26.0.000 as soon as Oracle releases it. Restrict and monitor local and administrative logon access to servers hosting HFM, since exploitation requires high privilege plus user interaction. Train users with access to these systems to be alert to social-engineering attempts that could supply the required human-interaction step, and review privileged account activity on HFM infrastructure for anomalies.

Affected
Oracle Hyperion Financial Management (component: Security)11.2.26.0.000
Estimated exposure
nichelikely low thousands of on-prem enterprise deployments (no public count) — Hyperion Financial Management is licensed enterprise on-prem EPM software deployed per organization in finance departments, and installations are not internet-scannable or publicly counted, so exposure is inherently limited to HFM customer…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.