ZeroHour

CVE-2026-87213

moderate

Hard-to-Exploit Unauthenticated Data Access Flaw in Oracle Hyperion Financial Management

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87213 is a vulnerability in the Security component of Oracle Hyperion Financial Management (HFM), affecting supported version 11.2.26.0.000. It is remotely exploitable without authentication: an unauthenticated attacker with network access via HTTP who successfully compromises HFM can gain unauthorized ability to create, delete, or modify critical data (or all HFM-accessible data) as well as unauthorized read access to critical data or complete access to all HFM-accessible data. Oracle rates the flaw as difficult to exploit (Attack Complexity: High), which yields a CVSS 3.1 base score of 7.4 (high) with high confidentiality and integrity impact and no availability impact. Organizations running the affected on-premises 11.2.26.0.000 deployment are exposed wherever the HFM web tier is reachable over HTTP, including any internet-facing instances. There is no known public proof of concept, the CVE is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported to date.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87213 and move off HFM 11.2.26.0.000 to the latest 11.2.x patch level, confirming the exact fixed build in Oracle's advisory. Restrict HTTP access to the HFM web tier (VPN, IP allowlisting, internal-only routing) so it is not reachable by unauthenticated network clients, since the attack requires only network access over HTTP. Review HFM application and access logs for anomalous unauthenticated activity or unexpected changes to financial consolidation data, and verify whether your 11.2.26.0.000 environment has any internet-facing components.

Affected
Oracle Hyperion Financial Management (component: Security)11.2.26.0.000
Estimated exposure
moderateon the order of a few thousand deployments worldwide (Oracle EPM/Hyperion customer base), with only a small subset of web tiers internet-exposed — Oracle Hyperion Financial Management is licensed, on-premises enterprise performance management software deployed mainly at large and mid-sized finance organizations, and public internet scans typically show only a small number of exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.