CVE-2026-87193
nicheUnauthenticated Data Exposure in Oracle Hyperion Financial Management (Security)
A flaw in the Security component of Oracle Hyperion Financial Management allows an unauthenticated attacker with network access via HTTP to read data from the application. Oracle rates the vulnerability as easily exploitable, requiring no privileges and no user interaction, but the impact is limited to confidentiality: successful attacks can expose critical data or all HFM-accessible data, with no integrity or availability impact. Only version 11.2.26.0.000 is listed as affected. Hyperion Financial Management is an enterprise financial consolidation product deployed mainly inside large corporate finance environments, so most instances sit on internal networks, though any internet-facing deployment would be directly reachable. No public proof-of-concept exists and the CVE is not in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.
What to do: Apply the Oracle Critical Patch Update that remediates this CVE and move affected 11.2.26.0.000 installations to the patched release. Until patched, restrict HTTP access to HFM to trusted internal networks or VPN, front the deployment with an authenticated reverse proxy or SSO, and audit logs for unauthenticated requests to HFM security endpoints. Given the product holds sensitive consolidated financial data, verify that no unexplained data access has occurred.
| Oracle Hyperion Financial Management (component: Security) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.