ZeroHour

CVE-2026-87212

moderate

Unauthenticated SQL Injection in Oracle Hyperion Financial Management Security Component

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

Oracle Hyperion Financial Management version 11.2.26.0.000 contains a vulnerability in its Security component that allows an unauthenticated attacker with network access to attack the product via SQL (an SQL injection-style flaw). The vulnerability is rated difficult to exploit (Attack Complexity: High), meaning an attacker would need specialized conditions or repeated attempts to succeed. If exploited, it grants unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data accessible through Oracle Hyperion Financial Management, with high impacts on confidentiality and integrity (CVSS 3.1 base score 7.4). The flaw affects only the supported version 11.2.26.0.000 of Oracle Hyperion Financial Management, an enterprise financial close and consolidation product typically deployed on-premises. There is no evidence of in-the-wild exploitation, the CVE is not on the CISA Known Exploited Vulnerabilities list, and no public proof-of-concept is known.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE as soon as it is available, since Oracle ships Hyperion fixes through its quarterly CPU cycle and only version 11.2.26.0.000 is listed as affected. In the interim, restrict network access to Hyperion Financial Management application and database/SQL endpoints to trusted internal networks or VPN, and ensure the backend database is not reachable from untrusted segments. Review application and database logs for anomalous SQL activity originating from the HFM tier and verify no unauthorized data changes or account modifications have occurred.

Affected
Oracle Hyperion Financial Management
Estimated exposure
moderate≈1,000–5,000 enterprise installations worldwide (order of thousands of systems) — Oracle Hyperion Financial Management is a specialized on-premises enterprise financial consolidation product with a customer base of large organizations numbering in the low thousands globally, and deployments are typically internal-facing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.