CVE-2026-87187
moderateUnauthenticated Adjacent-Network Takeover in Oracle Hyperion Financial Management 11.2
Oracle Hyperion Financial Management 11.2.26.0.000 contains an easily exploitable flaw in its Security component that lets an unauthenticated attacker who can reach the network segment attached to the server compromise the application. Exploitation requires no privileges and no user interaction, and successful attacks can result in a complete takeover of Oracle Hyperion Financial Management with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8, vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The adjacent-network attack vector means the attacker must be on the same physical communication segment (e.g., a compromised host or rogue device on the corporate LAN/VLAN hosting the HFM server) rather than the open internet. Only the supported version 11.2.26.0.000 is listed as affected. There is no known public proof of concept, the flaw is not on CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates this CVE and move off version 11.2.26.0.000 of Hyperion Financial Management as soon as the fixed release is available. Because exploitation requires adjacency to the server's network segment, restrict access to HFM server VLANs with segmentation, host firewalls, and 802.1X/zero-trust controls so only trusted finance and administrative clients can reach it. Audit logs for unauthenticated or anomalous requests to HFM services from LAN sources and verify whether 11.2.26.0.000 is running in your estate.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.