CVE-2026-87189
moderatePrivileged Remote Takeover Flaw in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87189 is a critical (CVSS 9.1) vulnerability in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. It is easily exploitable by a high-privileged attacker who has network access to the product via Oracle Net, meaning exploitation requires an authenticated and already-privileged account rather than anonymous access. Successful attacks result in a complete takeover of Oracle Hyperion Financial Management, with high impacts to confidentiality, integrity, and availability, and because of a scope change the blast radius can extend beyond HFM to additional products in the environment. Organizations running on-premises Oracle Hyperion Financial Management 11.2.26.0.000 are affected. There is no known public proof-of-concept, the CVE is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates this issue and move off 11.2.26.0.000 to the latest patched 11.2.x release as soon as it is available for your environment. Restrict Oracle Net listener and HFM service ports to trusted management networks via segmentation and firewall rules, since the attack path requires network access via Oracle Net. Audit and tightly control privileged HFM accounts, and review logs for anomalous activity by high-privilege users given the takeover and cross-product scope-change risk.
| Oracle Hyperion Financial Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.