CVE-2026-87208
nicheAuthenticated Unauthorized Data Access in Oracle Hyperion Financial Management 11.2.26
A vulnerability in the Security component of Oracle Hyperion Financial Management allows a low-privileged, authenticated attacker with network access via HTTP to compromise the application. Successful exploitation gives the attacker unauthorized read access to critical data or complete access to all data the product can reach, plus unauthorized update, insert, or delete access to some of that data. The flaw affects only the supported version 11.2.26.0.000, and Oracle rates it CVSS 3.1 7.1 (high) with high confidentiality and low integrity impact and no availability impact. Because it requires valid low-privilege credentials, it is most dangerous in environments where many users hold basic accounts against finance systems holding sensitive consolidation and reporting data. There is no known public proof-of-concept and no evidence of in-the-wild exploitation, and it is not on the CISA Known Exploited Vulnerabilities catalog.
What to do: Apply the Oracle Critical Patch Update that addresses this flaw and move off release 11.2.26.0.000 to a patched 11.2.x build. Restrict HTTP access to Hyperion Financial Management endpoints to trusted internal networks and VPNs, and enforce least-privilege role assignments so ordinary users cannot reach sensitive application components. Review audit logs for unexpected data reads or modifications performed by low-privileged accounts.
| Oracle Hyperion Financial Management (Oracle Hyperion) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.