ZeroHour

CVE-2026-87205

niche

Unauthenticated Data Disclosure in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87205 is a vulnerability in the Security component of Oracle Hyperion Financial Management (HFM), part of Oracle's Enterprise Performance Management suite, affecting supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. Successful exploitation allows unauthorized access to critical data or complete read access to all data accessible to the HFM application; the CVSS 3.1 base score is 7.5 with high confidentiality impact only (no integrity or availability impact). Organizations running the affected on-premises version are exposed, particularly if HFM HTTP endpoints are reachable beyond trusted internal networks. No public proof-of-concept exists and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply Oracle's latest Critical Patch Update for Hyperion Financial Management 11.2.x to remediate this flaw in the Security component of version 11.2.26.0.000. Restrict HTTP access to HFM endpoints so they are reachable only from trusted internal networks or VPNs rather than the internet. Review access logs for unauthenticated requests to the Security component and verify no unauthorized data access has occurred.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
niche≈ low-thousands of enterprise deployments worldwide (order of magnitude: a few thousand organizations) — Oracle Hyperion Financial Management is on-premises financial consolidation software used mainly by large corporate finance departments, so the install base is a small population of enterprises with no public install counts available; this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.