ZeroHour

CVE-2026-87192

niche

Low-Privilege Data Exposure and Partial DoS in Oracle Hyperion Financial Management

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87192 is a vulnerability in the Security component of Oracle Hyperion Financial Management, a financial consolidation and reporting application within Oracle's Hyperion/EPM suite. A low-privileged attacker with network access via HTTP can exploit it easily (CVSS 3.1: 7.1, AV:N/AC:L/PR:L) to gain unauthorized access to critical data — potentially complete access to all data the product can reach — and to cause a partial denial of service. Exploitation requires valid low-privilege credentials, so the attacker is likely an insider or someone who has compromised an account. Only supported version 11.2.26.0.000 is listed as affected. There is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87192 to Hyperion Financial Management 11.2.26.0.000 as soon as your patch cycle allows. Restrict HTTP access to HFM services to trusted internal networks and VPNs, audit low-privilege accounts for suspicious data access or unexpected session activity, and enforce least-privilege role assignments in the HFM security model.

Affected
Oracle Hyperion Financial Management (component: Security)11.2.26.0.000
Estimated exposure
niche≈ low thousands of enterprise installations globally, most deployed on internal networks — Oracle Hyperion Financial Management is an on-premises enterprise financial consolidation product licensed to large organizations rather than a mass-market product, and instances are rarely internet-exposed in public scan data, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.