ZeroHour

CVE-2026-87200

niche

Unauthenticated Data Tampering in Oracle Hyperion Financial Management

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87200 is a vulnerability in the Security component of Oracle Hyperion Financial Management (HFM), affecting supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack allows the attacker to create, delete, or modify critical data — or all data accessible to HFM — and to cause a partial denial of service; there is no confidentiality impact (CVSS 3.1: 8.2, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L). Organizations running the affected release of HFM, typically large-enterprise finance departments, are impacted. The flaw is not in the CISA KEV catalog, no public proof-of-concept is known, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update release that addresses this CVE to all Hyperion Financial Management 11.2.26.0.000 installations. In the interim, restrict HTTP access to HFM endpoints via firewall rules or a reverse proxy so only trusted finance-network users and VPN clients can reach them. Review HFM data and audit logs for unauthorized creations, deletions, or modifications that could indicate prior tampering.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
niche≈ low thousands of enterprise deployments globally; likely only hundreds internet-exposed — Oracle Hyperion Financial Management is on-premises enterprise performance management software used mainly by large-corporate finance functions, with no public install counts and most instances expected to sit on internal networks rather…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.