CVE-2026-87183
nicheHigh-Privilege Local Takeover Flaw in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87183 is a vulnerability in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. It is easily exploitable by an attacker who already holds high privileges and can log on to the infrastructure where HFM executes, but a successful attack also requires human interaction from someone other than the attacker, implying a social-engineering or user-assisted component. If exploited, the attacker can fully compromise Oracle Hyperion Financial Management (takeover with high confidentiality, integrity, and availability impact), and because of a scope change, successful attacks may also significantly impact additional products beyond HFM. The affected population is limited to organizations running the on-premises HFM 11.2.26.0.000 release. The flaw is not listed in CISA's KEV catalog and no public proof-of-concept is known, so there is no evidence of active exploitation.
What to do: Apply the Oracle Critical Patch Update that remediates this issue in Hyperion Financial Management 11.2.26.0.000 as soon as Oracle releases it. Restrict and monitor local and administrative logon access to servers hosting HFM, since exploitation requires high privilege plus user interaction. Train users with access to these systems to be alert to social-engineering attempts that could supply the required human-interaction step, and review privileged account activity on HFM infrastructure for anomalies.
| Oracle Hyperion Financial Management (component: Security) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.