ZeroHour

CVE-2026-87201

moderate

Authenticated Privilege Escalation in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87201 is a vulnerability in the Security component of Oracle Hyperion Financial Management, a enterprise financial consolidation and close application. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, who can escalate to a full compromise of the Oracle Hyperion Financial Management instance, with high impact on confidentiality, integrity, and availability. Only the supported version 11.2.26.0.000 is listed as affected. Successful exploitation effectively hands the attacker takeover of the application and its financial data. There is no evidence of exploitation in the wild and no public proof of concept is known, but the vulnerability carries a high CVSS 3.1 base score of 8.8.

What to do: Apply the Oracle Critical Patch Update (CPU) that remedies CVE-2026-87201 to any Hyperion Financial Management instance running 11.2.26.0.000 as soon as it is available. Restrict network access to Hyperion HTTP endpoints (e.g., via VPN, IP allowlisting, or reverse proxy with authentication) and enforce least-privilege role assignments. Review audit and access logs for anomalous activity by low-privileged accounts that could indicate an attempted exploitation.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
moderateroughly low thousands of installations globally (a few thousand enterprise EPM deployments), with only a small fraction directly internet-exposed — Oracle Hyperion Financial Management is on-premises enterprise performance management software typically deployed by mid-to-large finance organizations, so the install base is measured in the low thousands of sites and is usually deployed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.