ZeroHour

CVE-2026-87211

moderate

Unauthenticated Data Disclosure in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87211 is a vulnerability in the Security component of Oracle Hyperion Financial Management, affecting only version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N). Successful exploitation gives the attacker unauthorized access to critical data, up to complete access to all data reachable through Oracle Hyperion Financial Management; the impact is confidentiality-only, with no effect on integrity or availability. Affected parties are enterprises running the on-premises Hyperion Financial Management consolidation software, typically finance departments at large organizations. No public proof-of-concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no exploitation has been reported to date.

What to do: Apply the Oracle Critical Patch Update that remediates this issue for Hyperion Financial Management 11.2.26.0.000 as soon as it is available. Until patched, restrict HTTP access to Hyperion Financial Management endpoints to trusted finance users via VPN or an authenticating reverse proxy, since the flaw requires no credentials. Review web-server and application logs for unusual unauthenticated HTTP requests to the Security component, which may indicate probing for this flaw.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
moderatelikely low thousands of enterprise installations worldwide (order of 1,000–10,000 servers), with only a small fraction internet-facing — Oracle Hyperion Financial Management is on-premises enterprise financial-close software deployed at thousands of large organizations, usually on internal corporate networks; no public active-install counts or scan data were available, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.