CVE-2026-87217
nicheUnauthenticated Data Access Flaw in Oracle Hyperion Financial Management 11.2
CVE-2026-87217 is a critical vulnerability in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. It is exploitable over the network via HTTP by an unauthenticated attacker with no user interaction required. A successful attack lets the attacker read, create, delete, or modify critical data — up to complete access to all data reachable through the HFM application — though availability is not impacted (CVSS 9.1, C:H/I:H/A:N). Organizations running the affected on-premises version, particularly any instance with HTTP endpoints reachable beyond the internal network, are at risk. No public proof of concept is known, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported to date.
What to do: Apply the Oracle Critical Patch Update that remediates this flaw for Hyperion Financial Management 11.2 and move off 11.2.26.0.000 as soon as the fixed patch level is available. Restrict network access to HFM HTTP endpoints (VPN, firewall allow-listing, or reverse proxy with authentication) so the application is not reachable by unauthenticated users. Review audit and data-change logs for unexpected account or data modifications since the exposure window began.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.