CVE-2026-87188
nicheCritical Unauthenticated Flaw in Oracle Hyperion Financial Management Security Component
CVE-2026-87188 is a critical (CVSS 9.8) vulnerability in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction, and successful attacks result in complete takeover of the Oracle Hyperion Financial Management application with high impact to confidentiality, integrity, and availability. In practice, this means an attacker who can reach an exposed HFM web endpoint could seize control of the financial consolidation system and its data. Affected organizations are enterprises running Oracle Hyperion Financial Management 11.2.26.0.000 on-premises. No public proof-of-concept exists and the flaw is not on the CISA KEV catalog, so exploitation is not currently known to be occurring in the wild.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87188 to Hyperion Financial Management 11.2.26.0.000 as soon as it is available, since the flaw is rated critical and unauthenticated. Restrict network access so HFM HTTP endpoints are reachable only from trusted internal networks or VPN rather than the internet. Review web server and application logs for unauthenticated requests targeting the Security component to check for any suspicious access, and verify that no HFM 11.2.26.0.000 instance is unintentionally internet-facing.
| Oracle Hyperion Financial Management (component: Security) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.