CVE-2026-87214
nicheHigh-Privilege Takeover Flaw in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87214 is a vulnerability in the Security component of Oracle Hyperion Financial Management (HFM), affecting supported version 11.2.26.0.000. It is easily exploitable by an attacker who already holds high privileges and has network access to the product over HTTP, allowing them to fully compromise the HFM installation. The CVSS 3.1 base score is 9.1 (critical), and the scope is changed, meaning successful attacks can significantly impact additional products beyond Oracle Hyperion Financial Management. Because exploitation requires high privileges, the realistic attack path is a privileged insider or an attacker who has already obtained admin-level credentials pivoting into broader compromise of the Hyperion environment. The flaw is not on the CISA KEV list and no public proof-of-concept is known, so there is no indication of active exploitation.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87214 to your Oracle Hyperion Financial Management 11.2.26.0.000 environment as soon as it is available, prioritizing systems reachable over HTTP. Restrict network access to HFM services to trusted internal segments or VPN, enforce HTTPS/TLS, and apply strict least-privilege and MFA controls on high-privileged HFM accounts since they are the attack prerequisite. Given the scope-change rating, also review and harden adjacent integrated systems and monitor privileged-account activity for signs of post-compromise lateral movement.
| Oracle Hyperion Financial Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.