ZeroHour

CVE-2026-87184

moderate

Unauthenticated SQL Injection in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-87184 is an easily exploitable SQL injection in the Security component of Oracle Hyperion Financial Management (HFM), affecting version 11.2.26.0.000. An unauthenticated remote attacker with network access to the product can send crafted SQL input and compromise the HFM application. A successful attack can result in a complete takeover of Oracle Hyperion Financial Management, with high impact on confidentiality, integrity, and availability of the financial consolidation environment. Organizations running the affected on-premises version are exposed, particularly if HFM endpoints are reachable beyond internal finance networks. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and no active exploitation has been reported as of this analysis.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw for Hyperion Financial Management 11.2.26 as soon as it is available. Restrict network access to HFM web and data-tier ports to trusted internal segments, since the flaw requires no authentication. Review database and application logs for anomalous SQL statements originating from unauthenticated sessions, and verify that the running version is not 11.2.26.0.000.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
moderate≈1,000–10,000 enterprise HFM deployments (order of magnitude: low thousands of organizations) — Estimated from Oracle Hyperion's enterprise EPM customer base (typically large corporate finance departments) and the product's usual internal-facing, on-premises deployment pattern; no public active-install counts or scan figures were…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.