ZeroHour

CVE-2026-87219

moderate

Local Privilege Escalation in Oracle Hyperion Financial Management Security Component

CVSS 3.1
8.4 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87219 is a high-severity (CVSS 8.4) flaw in the Security component of Oracle Hyperion Financial Management, affecting version 11.2.26.0.000. It is easily exploitable by a low-privileged attacker who already has logon access to the server infrastructure where Hyperion Financial Management runs, meaning it is a local attack vector rather than a remotely exploitable internet-facing bug. A successful exploit lets the attacker fully compromise Hyperion Financial Management and, due to a scope change, can significantly impact additional products beyond HFM itself. The attacker gains unauthorized creation, deletion, or modification of critical data — or complete read access to all data accessible to HFM — with high impact to both confidentiality and integrity (availability is unaffected). No public proof-of-concept exists and the vulnerability is not on the CISA KEV catalog, so exploitation is not known to be occurring.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87219 to any Hyperion Financial Management 11.2.26.0.000 environments. Enforce least-privilege on local OS and application accounts on servers hosting Hyperion, since exploitation requires local logon with low privileges. Review audit logs for unauthorized data creation, modification, or access in HFM-accessible data and check whether other products sharing that infrastructure were affected via scope change.

Affected
Oracle Hyperion Financial Management (component: Security)
Estimated exposure
moderatelikely low thousands of enterprise HFM deployments worldwide (tens of thousands of finance users) — Oracle Hyperion Financial Management is on-premises enterprise performance management software deployed mainly at large and mid-size finance organizations, with no public active-install counts or internet-exposed scan data available, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.