ZeroHour

CVE-2026-87214

niche

High-Privilege Takeover Flaw in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-87214 is a vulnerability in the Security component of Oracle Hyperion Financial Management (HFM), affecting supported version 11.2.26.0.000. It is easily exploitable by an attacker who already holds high privileges and has network access to the product over HTTP, allowing them to fully compromise the HFM installation. The CVSS 3.1 base score is 9.1 (critical), and the scope is changed, meaning successful attacks can significantly impact additional products beyond Oracle Hyperion Financial Management. Because exploitation requires high privileges, the realistic attack path is a privileged insider or an attacker who has already obtained admin-level credentials pivoting into broader compromise of the Hyperion environment. The flaw is not on the CISA KEV list and no public proof-of-concept is known, so there is no indication of active exploitation.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87214 to your Oracle Hyperion Financial Management 11.2.26.0.000 environment as soon as it is available, prioritizing systems reachable over HTTP. Restrict network access to HFM services to trusted internal segments or VPN, enforce HTTPS/TLS, and apply strict least-privilege and MFA controls on high-privileged HFM accounts since they are the attack prerequisite. Given the scope-change rating, also review and harden adjacent integrated systems and monitor privileged-account activity for signs of post-compromise lateral movement.

Affected
Oracle Hyperion Financial Management11.2.26.0.000
Estimated exposure
nichelow thousands of on-premises HFM deployments globally, with an internet-exposed subset likely in the hundreds to low thousands — Oracle Hyperion Financial Management is on-premises enterprise financial-close/consolidation software deployed mainly at large finance organizations, typically on internal networks; no public install counts or scan data are available, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.