CVE-2026-87197
nicheUnauthenticated Data Access Flaw in Oracle Hyperion Financial Management
A vulnerability in the Security component of Oracle Hyperion Financial Management allows an unauthenticated attacker with network access via HTTP to compromise the application. Exploitation requires no privileges, no user interaction, and is rated easy (CVSS 3.1 base score 8.2). A successful attack can result in unauthorized read access to critical data or all Oracle Hyperion Financial Management accessible data, as well as unauthorized update, insert, or delete access to some of that data; availability is not impacted. Only supported version 11.2.26.0.000 is listed as affected. No public proof of concept is known, the flaw is not in CISA's KEV catalog, and no active exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates this CVE to Oracle Hyperion Financial Management 11.2.26.0.000 as soon as it is available. Restrict HTTP access to HFM services to trusted internal networks or VPN, and avoid exposing them directly to the internet. Review application and access logs for unauthenticated requests to HFM endpoints and any unexpected data reads or modifications.
| Oracle Hyperion Financial Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.