CVE-2026-87194
nicheUnauthenticated Data Disclosure in Oracle Hyperion Financial Management Security Component
CVE-2026-87194 is an unauthenticated information disclosure flaw in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. An unauthenticated remote attacker with network access to the product's HTTP interface can exploit the flaw with low complexity and no user interaction, and successful attacks can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. The CVSS 3.1 base score is 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), indicating a confidentiality-only impact with no effect on integrity or availability. Organizations running the affected on-premises version of Hyperion Financial Management — typically large enterprises using it for financial consolidation and close — are at risk, especially if the web tier is reachable from untrusted networks. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is currently unknown rather than confirmed.
What to do: Apply the fix for CVE-2026-87194 from Oracle's latest Critical Patch Update for Hyperion if you run version 11.2.26.0.000, as the vulnerability is rated easily exploitable and requires no authentication. Until patched, restrict HTTP access to Hyperion Financial Management web endpoints to trusted VPN or internal networks and never expose them directly to the internet. Review web server and application logs for anomalous unauthenticated requests or data retrieval from affected instances.
| Oracle Hyperion Financial Management (component: Security) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.