ZeroHour

CVE-2026-87187

moderate

Unauthenticated Adjacent-Network Takeover in Oracle Hyperion Financial Management 11.2

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Oracle Hyperion Financial Management 11.2.26.0.000 contains an easily exploitable flaw in its Security component that lets an unauthenticated attacker who can reach the network segment attached to the server compromise the application. Exploitation requires no privileges and no user interaction, and successful attacks can result in a complete takeover of Oracle Hyperion Financial Management with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8, vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The adjacent-network attack vector means the attacker must be on the same physical communication segment (e.g., a compromised host or rogue device on the corporate LAN/VLAN hosting the HFM server) rather than the open internet. Only the supported version 11.2.26.0.000 is listed as affected. There is no known public proof of concept, the flaw is not on CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE and move off version 11.2.26.0.000 of Hyperion Financial Management as soon as the fixed release is available. Because exploitation requires adjacency to the server's network segment, restrict access to HFM server VLANs with segmentation, host firewalls, and 802.1X/zero-trust controls so only trusted finance and administrative clients can reach it. Audit logs for unauthenticated or anomalous requests to HFM services from LAN sources and verify whether 11.2.26.0.000 is running in your estate.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
moderateLikely low thousands of enterprise deployments worldwide (order of 1,000–10,000 instances) — Oracle Hyperion Financial Management is an on-premises enterprise performance management product typically deployed by large finance organizations, a customer base conventionally measured in the low thousands globally, and no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.