ZeroHour

CVE-2026-87188

niche

Critical Unauthenticated Flaw in Oracle Hyperion Financial Management Security Component

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-87188 is a critical (CVSS 9.8) vulnerability in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction, and successful attacks result in complete takeover of the Oracle Hyperion Financial Management application with high impact to confidentiality, integrity, and availability. In practice, this means an attacker who can reach an exposed HFM web endpoint could seize control of the financial consolidation system and its data. Affected organizations are enterprises running Oracle Hyperion Financial Management 11.2.26.0.000 on-premises. No public proof-of-concept exists and the flaw is not on the CISA KEV catalog, so exploitation is not currently known to be occurring in the wild.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87188 to Hyperion Financial Management 11.2.26.0.000 as soon as it is available, since the flaw is rated critical and unauthenticated. Restrict network access so HFM HTTP endpoints are reachable only from trusted internal networks or VPN rather than the internet. Review web server and application logs for unauthenticated requests targeting the Security component to check for any suspicious access, and verify that no HFM 11.2.26.0.000 instance is unintentionally internet-facing.

Affected
Oracle Hyperion Financial Management (component: Security)11.2.26.0.000
Estimated exposure
nichelow thousands of enterprise HFM deployments worldwide, with only a subset (likely hundreds) of web endpoints internet-exposed — clearly an estimate — Oracle Hyperion Financial Management is an enterprise financial consolidation product deployed on-premises by a relatively small population of large corporate finance organizations, and public internet scans historically show only a small…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.