CVE-2026-87210
moderateUnauthenticated Data-Access Flaw in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87210 is a vulnerability in the Security component of Oracle Hyperion Financial Management affecting version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker who has access to the same physical network segment as the server running Hyperion Financial Management (CVSS 3.1 base score 8.3, vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). A successful attack lets the attacker create, delete, or modify critical data (or all Hyperion-accessible data), read critical or all accessible data, and cause a partial denial of service. The issue is limited to on-premises deployments of the affected 11.2.26.0.000 release reachable from the local network segment. There is no known public proof of concept, the flaw is not in the CISA KEV catalog, and no exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that addresses this flaw and move off the affected 11.2.26.0.000 release as soon as a fixed bundle patch is available. Until patched, isolate Hyperion Financial Management servers on a dedicated VLAN or subnet reachable only by authorized finance users and administrators, and block unneeded lateral access from general corporate networks. Review audit logs and data-change history in Hyperion for unauthorized modifications or access since the vulnerable version was deployed.
| Oracle Hyperion Financial Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.