ZeroHour

CVE-2026-87186

niche

Unauthenticated Adjacent-Network Takeover Flaw in Oracle Hyperion Financial Management

CVSS 3.1
9.6 critical
EPSS
Published
()
Modified
AI analysis

A critical vulnerability (CVSS 9.6) in the Security component of Oracle Hyperion Financial Management 11.2.26.0.000 lets an unauthenticated attacker who can reach the network segment attached to the HFM hardware compromise the application with low attack complexity and no user interaction. Successful exploitation results in a complete takeover of Oracle Hyperion Financial Management, with high impacts on confidentiality, integrity, and availability. Because the vulnerability's scope changes, successful attacks may also significantly impact additional products beyond HFM itself. Organizations running the supported release 11.2.26.0.000 on their internal networks are affected. No public proof-of-concept is known and the CVE is not on the CISA Known Exploited Vulnerabilities list, so no in-the-wild exploitation has been observed.

What to do: Apply the Oracle Critical Patch Update (CPU) release that remediates CVE-2026-87186 to every Hyperion Financial Management 11.2.26.0.000 deployment as soon as the patch is available, since no fixed version is named in the advisory. In the interim, tightly restrict which hosts can reach the HFM servers by segmenting the VLAN and enforcing host-based firewall allowlists on the communication segment attached to the HFM hardware. Audit HFM and adjacent EPM logs for unexplained privileged access or configuration changes, and patch the scope-changed downstream products per Oracle's related guidance.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)
Estimated exposure
niche≈ low thousands of enterprise on-premises deployments (order of magnitude 10³) — Hyperion Financial Management is a licensed enterprise financial-consolidation suite deployed on internal networks at large organizations rather than a mass-market product, and no public install counts or internet-exposed scan data exist…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.