CVE-2026-87186
nicheUnauthenticated Adjacent-Network Takeover Flaw in Oracle Hyperion Financial Management
A critical vulnerability (CVSS 9.6) in the Security component of Oracle Hyperion Financial Management 11.2.26.0.000 lets an unauthenticated attacker who can reach the network segment attached to the HFM hardware compromise the application with low attack complexity and no user interaction. Successful exploitation results in a complete takeover of Oracle Hyperion Financial Management, with high impacts on confidentiality, integrity, and availability. Because the vulnerability's scope changes, successful attacks may also significantly impact additional products beyond HFM itself. Organizations running the supported release 11.2.26.0.000 on their internal networks are affected. No public proof-of-concept is known and the CVE is not on the CISA Known Exploited Vulnerabilities list, so no in-the-wild exploitation has been observed.
What to do: Apply the Oracle Critical Patch Update (CPU) release that remediates CVE-2026-87186 to every Hyperion Financial Management 11.2.26.0.000 deployment as soon as the patch is available, since no fixed version is named in the advisory. In the interim, tightly restrict which hosts can reach the HFM servers by segmenting the VLAN and enforcing host-based firewall allowlists on the communication segment attached to the HFM hardware. Audit HFM and adjacent EPM logs for unexplained privileged access or configuration changes, and patch the scope-changed downstream products per Oracle's related guidance.
| Oracle Hyperion Financial Management (Oracle Hyperion) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.