ZeroHour

CVE-2026-87193

niche

Unauthenticated Data Exposure in Oracle Hyperion Financial Management (Security)

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

A flaw in the Security component of Oracle Hyperion Financial Management allows an unauthenticated attacker with network access via HTTP to read data from the application. Oracle rates the vulnerability as easily exploitable, requiring no privileges and no user interaction, but the impact is limited to confidentiality: successful attacks can expose critical data or all HFM-accessible data, with no integrity or availability impact. Only version 11.2.26.0.000 is listed as affected. Hyperion Financial Management is an enterprise financial consolidation product deployed mainly inside large corporate finance environments, so most instances sit on internal networks, though any internet-facing deployment would be directly reachable. No public proof-of-concept exists and the CVE is not in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE and move affected 11.2.26.0.000 installations to the patched release. Until patched, restrict HTTP access to HFM to trusted internal networks or VPN, front the deployment with an authenticated reverse proxy or SSO, and audit logs for unauthenticated requests to HFM security endpoints. Given the product holds sensitive consolidated financial data, verify that no unexplained data access has occurred.

Affected
Oracle Hyperion Financial Management (component: Security)
Estimated exposure
nichelikely a few thousand enterprise deployments globally, with only hundreds to low thousands of internet-exposed instances — Hyperion Financial Management is on-premises enterprise EPM software used primarily by large corporate finance departments, and public internet scan data for Oracle Hyperion/EPM servers historically shows only a few hundred to low…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.