ZeroHour

CVE-2026-87195

niche

Unauthenticated Data Tampering Flaw in Oracle Hyperion Financial Management Security

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

A difficult-to-exploit vulnerability in the Security component of Oracle Hyperion Financial Management allows an unauthenticated attacker with network access via TLS to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification of critical data or all HFM-accessible data, as well as unauthorized read access to critical data, giving high confidentiality and integrity impact (CVSS 3.1: 7.4, availability unaffected). Only version 11.2.26.0.000 is listed as affected. The high attack complexity means reliable exploitation requires favorable conditions, but no authentication or user interaction is needed, so internet-reachable instances remain at risk. There is no known public proof of concept and no evidence of exploitation in the wild.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87195 to move off affected version 11.2.26.0.000. Restrict network access to Hyperion Financial Management TLS endpoints (VPN or IP allowlisting) and ensure the service is not exposed to the internet. Review HFM audit and application logs for unexplained data creation, modification, or deletion by unauthenticated sessions.

Affected
Oracle Hyperion Financial Management11.2.26.0.000
Estimated exposure
nichelikely low thousands of enterprise installations (no public install counts) — Oracle HFM is specialized on-premises enterprise performance management software used by large finance organizations rather than a mass-market product, and no public installation counts or internet-exposed device scan figures are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.