CVE-2026-87213
moderateHard-to-Exploit Unauthenticated Data Access Flaw in Oracle Hyperion Financial Management
CVE-2026-87213 is a vulnerability in the Security component of Oracle Hyperion Financial Management (HFM), affecting supported version 11.2.26.0.000. It is remotely exploitable without authentication: an unauthenticated attacker with network access via HTTP who successfully compromises HFM can gain unauthorized ability to create, delete, or modify critical data (or all HFM-accessible data) as well as unauthorized read access to critical data or complete access to all HFM-accessible data. Oracle rates the flaw as difficult to exploit (Attack Complexity: High), which yields a CVSS 3.1 base score of 7.4 (high) with high confidentiality and integrity impact and no availability impact. Organizations running the affected on-premises 11.2.26.0.000 deployment are exposed wherever the HFM web tier is reachable over HTTP, including any internet-facing instances. There is no known public proof of concept, the CVE is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported to date.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87213 and move off HFM 11.2.26.0.000 to the latest 11.2.x patch level, confirming the exact fixed build in Oracle's advisory. Restrict HTTP access to the HFM web tier (VPN, IP allowlisting, internal-only routing) so it is not reachable by unauthenticated network clients, since the attack requires only network access over HTTP. Review HFM application and access logs for anomalous unauthenticated activity or unexpected changes to financial consolidation data, and verify whether your 11.2.26.0.000 environment has any internet-facing components.
| Oracle Hyperion Financial Management (component: Security) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.