CVE-2026-87184
moderateUnauthenticated SQL Injection in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87184 is an easily exploitable SQL injection in the Security component of Oracle Hyperion Financial Management (HFM), affecting version 11.2.26.0.000. An unauthenticated remote attacker with network access to the product can send crafted SQL input and compromise the HFM application. A successful attack can result in a complete takeover of Oracle Hyperion Financial Management, with high impact on confidentiality, integrity, and availability of the financial consolidation environment. Organizations running the affected on-premises version are exposed, particularly if HFM endpoints are reachable beyond internal finance networks. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and no active exploitation has been reported as of this analysis.
What to do: Apply the Oracle Critical Patch Update that remediates this flaw for Hyperion Financial Management 11.2.26 as soon as it is available. Restrict network access to HFM web and data-tier ports to trusted internal segments, since the flaw requires no authentication. Review database and application logs for anomalous SQL statements originating from unauthenticated sessions, and verify that the running version is not 11.2.26.0.000.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.