ZeroHour

CVE-2026-87185

niche

Privilege Escalation to Full Takeover in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Oracle Hyperion Financial Management version 11.2.26.0.000 contains a flaw in its Security component that allows a low-privileged, authenticated attacker with network access via HTTP to escalate to full compromise of the application. Exploitation is rated easy (low attack complexity, no user interaction) and requires only a valid low-privilege account plus reachability of the Hyperion web tier. A successful attack results in complete takeover of Oracle Hyperion Financial Management, with high impact on the confidentiality, integrity, and availability of financial close and consolidation data (CVSS 3.1 base score 8.8). Only the supported release 11.2.26.0.000 is listed as affected. There is no known public proof-of-concept, no confirmed in-the-wild exploitation, and the CVE is not on CISA's Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87185 to every Oracle Hyperion Financial Management 11.2.26.0.000 installation. Restrict HTTP access to the Hyperion web tier to trusted internal networks or VPN, tightly control which users hold even low-privileged accounts, and audit existing low-privilege account activity for anomalous access to administrative functions or sensitive financial data.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)
Estimated exposure
nichelikely low thousands of installations worldwide, with only hundreds plausibly internet-exposed — Hyperion Financial Management is on-premises enterprise financial consolidation software deployed mainly at mid-to-large organizations behind corporate perimeters, and public internet scan data typically shows only small numbers of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.