ZeroHour

CVE-2026-87206

niche

Unauthenticated Data-Access Flaw in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87206 is a vulnerability in the Security component of Oracle Hyperion Financial Management, affecting the supported release 11.2.26.0.000. It allows an unauthenticated attacker with network access via HTTP to compromise the product, though the CVSS vector (AC:H) indicates exploitation is difficult. A successful attack can give the attacker unauthorized ability to create, delete, or modify critical data — or all data accessible through Hyperion Financial Management — as well as unauthorized read access to that data, with high confidentiality and integrity impact (no availability impact). Organizations running HFM 11.2.26.0.000 with web-facing or broadly reachable HTTP endpoints are the ones at risk, though the difficulty of exploitation lowers practical risk. There is no known public proof of concept, no evidence of in-the-wild exploitation, and the flaw is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-87206 and move Hyperion Financial Management off 11.2.26.0.000 to the patched release. Restrict HTTP access to HFM web endpoints to trusted internal networks or VPN rather than exposing them broadly, since the attack requires only network reachability with no credentials. Review HFM audit and access logs around the Security component for unauthenticated requests or unexpected data creation, modification, or deletion.

Affected
Oracle Hyperion Financial Management (component: Security)11.2.26.0.000
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments worldwide, with only a small fraction internet-exposed — Hyperion Financial Management is on-premises enterprise performance management software licensed mainly to large finance organizations and typically deployed on internal networks, so the affected install base is far smaller than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.