ZeroHour

CVE-2026-87220

niche

Unauthenticated DoS and Data Modification in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87220 is a vulnerability in the Security component of Oracle Hyperion Financial Management (HFM), affecting supported version 11.2.26.0.000. An unauthenticated attacker who can reach the physical communication segment (i.e., the network segment/VLAN) attached to the server running HFM can exploit it with low complexity and no user interaction, without needing valid credentials. A successful attack can hang or repeatedly crash the application, causing a complete denial of service, and can also allow unauthorized update, insert, or delete access to some HFM-accessible data; confidentiality is not impacted. Only on-premises deployments of Hyperion Financial Management 11.2.26.0.000 are affected, and the adjacent-network attack vector means exposure is limited to attackers already on the internal network segment hosting the HFM servers. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so exploitation in the wild is not known.

What to do: Apply Oracle's Critical Patch Update that addresses CVE-2026-87220 and move off affected version 11.2.26.0.000 as soon as the patched release is available. Until patched, restrict which hosts can reach HFM services by placing the servers in a dedicated, tightly filtered network segment (VLAN/firewall rules limiting access to known admin and client sources), since exploitation requires only adjacency on that segment. Monitor HFM application and service logs for unexplained hangs, repeated crashes, or unexpected data modifications, and check whether any internal hosts on the HFM segment show anomalous activity.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
niche≈ low thousands of enterprise installations worldwide — Hyperion Financial Management is on-premises enterprise financial consolidation software typically deployed once (or in small clusters) per large finance organization, implying a global install base in the low thousands rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).

Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

In the news

No ingested article mentions this CVE yet.