CVE-2026-87196
moderateUnauthenticated Data Access Flaw in Oracle Hyperion Financial Management 11.2
Oracle Hyperion Financial Management version 11.2.26.0.000 contains an easily exploitable flaw in its Security component that lets an unauthenticated remote attacker with HTTP access to the server compromise the application. The vulnerability requires no privileges, no user interaction, and only low attack complexity, so any network-reachable HFM web front end is a viable target. Successful attacks can yield unauthorized read access to critical data — potentially all data accessible to Oracle Hyperion Financial Management — plus unauthorized update, insert, or delete access to some of that data (CVSS 3.1 base score 8.2, high confidentiality impact). Organizations running the affected on-premises version are at risk, especially where the HFM web tier is reachable from untrusted networks. No public proof-of-concept is known, the flaw is not on the CISA Known Exploited Vulnerabilities list, and there is no evidence of in-the-wild exploitation to date.
What to do: Apply the Oracle Critical Patch Update that remediates this flaw, upgrading from Hyperion Financial Management 11.2.26.0.000 to the patched 11.2.x release. Until patched, restrict HTTP access to the HFM web tier to trusted internal networks or VPN and front it with an authenticating reverse proxy if remote access is required. Review application and access logs for unauthenticated requests and any unexpected data reads or modifications since the system was exposed.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.