CVE-2026-87201
moderateAuthenticated Privilege Escalation in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87201 is a vulnerability in the Security component of Oracle Hyperion Financial Management, a enterprise financial consolidation and close application. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, who can escalate to a full compromise of the Oracle Hyperion Financial Management instance, with high impact on confidentiality, integrity, and availability. Only the supported version 11.2.26.0.000 is listed as affected. Successful exploitation effectively hands the attacker takeover of the application and its financial data. There is no evidence of exploitation in the wild and no public proof of concept is known, but the vulnerability carries a high CVSS 3.1 base score of 8.8.
What to do: Apply the Oracle Critical Patch Update (CPU) that remedies CVE-2026-87201 to any Hyperion Financial Management instance running 11.2.26.0.000 as soon as it is available. Restrict network access to Hyperion HTTP endpoints (e.g., via VPN, IP allowlisting, or reverse proxy with authentication) and enforce least-privilege role assignments. Review audit and access logs for anomalous activity by low-privileged accounts that could indicate an attempted exploitation.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.