CVE-2026-87206
nicheUnauthenticated Data-Access Flaw in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87206 is a vulnerability in the Security component of Oracle Hyperion Financial Management, affecting the supported release 11.2.26.0.000. It allows an unauthenticated attacker with network access via HTTP to compromise the product, though the CVSS vector (AC:H) indicates exploitation is difficult. A successful attack can give the attacker unauthorized ability to create, delete, or modify critical data — or all data accessible through Hyperion Financial Management — as well as unauthorized read access to that data, with high confidentiality and integrity impact (no availability impact). Organizations running HFM 11.2.26.0.000 with web-facing or broadly reachable HTTP endpoints are the ones at risk, though the difficulty of exploitation lowers practical risk. There is no known public proof of concept, no evidence of in-the-wild exploitation, and the flaw is not on the CISA Known Exploited Vulnerabilities catalog.
What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-87206 and move Hyperion Financial Management off 11.2.26.0.000 to the patched release. Restrict HTTP access to HFM web endpoints to trusted internal networks or VPN rather than exposing them broadly, since the attack requires only network reachability with no credentials. Review HFM audit and access logs around the Security component for unauthenticated requests or unexpected data creation, modification, or deletion.
| Oracle Hyperion Financial Management (component: Security) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.