ZeroHour

CVE-2026-87208

niche

Authenticated Unauthorized Data Access in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

A vulnerability in the Security component of Oracle Hyperion Financial Management allows a low-privileged, authenticated attacker with network access via HTTP to compromise the application. Successful exploitation gives the attacker unauthorized read access to critical data or complete access to all data the product can reach, plus unauthorized update, insert, or delete access to some of that data. The flaw affects only the supported version 11.2.26.0.000, and Oracle rates it CVSS 3.1 7.1 (high) with high confidentiality and low integrity impact and no availability impact. Because it requires valid low-privilege credentials, it is most dangerous in environments where many users hold basic accounts against finance systems holding sensitive consolidation and reporting data. There is no known public proof-of-concept and no evidence of in-the-wild exploitation, and it is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that addresses this flaw and move off release 11.2.26.0.000 to a patched 11.2.x build. Restrict HTTP access to Hyperion Financial Management endpoints to trusted internal networks and VPNs, and enforce least-privilege role assignments so ordinary users cannot reach sensitive application components. Review audit logs for unexpected data reads or modifications performed by low-privileged accounts.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)
Estimated exposure
nichelikely a few thousand enterprise deployments worldwide (estimate) — Hyperion Financial Management is on-premises enterprise performance management software typically deployed internally by large finance organizations, and no public install counts or exposed-device scan figures are available, so the number…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.