CVE-2026-87185
nichePrivilege Escalation to Full Takeover in Oracle Hyperion Financial Management 11.2.26
Oracle Hyperion Financial Management version 11.2.26.0.000 contains a flaw in its Security component that allows a low-privileged, authenticated attacker with network access via HTTP to escalate to full compromise of the application. Exploitation is rated easy (low attack complexity, no user interaction) and requires only a valid low-privilege account plus reachability of the Hyperion web tier. A successful attack results in complete takeover of Oracle Hyperion Financial Management, with high impact on the confidentiality, integrity, and availability of financial close and consolidation data (CVSS 3.1 base score 8.8). Only the supported release 11.2.26.0.000 is listed as affected. There is no known public proof-of-concept, no confirmed in-the-wild exploitation, and the CVE is not on CISA's Known Exploited Vulnerabilities catalog.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87185 to every Oracle Hyperion Financial Management 11.2.26.0.000 installation. Restrict HTTP access to the Hyperion web tier to trusted internal networks or VPN, tightly control which users hold even low-privileged accounts, and audit existing low-privilege account activity for anomalous access to administrative functions or sensitive financial data.
| Oracle Hyperion Financial Management (Oracle Hyperion) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.