CVE-2026-87220
nicheUnauthenticated DoS and Data Modification in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87220 is a vulnerability in the Security component of Oracle Hyperion Financial Management (HFM), affecting supported version 11.2.26.0.000. An unauthenticated attacker who can reach the physical communication segment (i.e., the network segment/VLAN) attached to the server running HFM can exploit it with low complexity and no user interaction, without needing valid credentials. A successful attack can hang or repeatedly crash the application, causing a complete denial of service, and can also allow unauthorized update, insert, or delete access to some HFM-accessible data; confidentiality is not impacted. Only on-premises deployments of Hyperion Financial Management 11.2.26.0.000 are affected, and the adjacent-network attack vector means exposure is limited to attackers already on the internal network segment hosting the HFM servers. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so exploitation in the wild is not known.
What to do: Apply Oracle's Critical Patch Update that addresses CVE-2026-87220 and move off affected version 11.2.26.0.000 as soon as the patched release is available. Until patched, restrict which hosts can reach HFM services by placing the servers in a dedicated, tightly filtered network segment (VLAN/firewall rules limiting access to known admin and client sources), since exploitation requires only adjacency on that segment. Monitor HFM application and service logs for unexplained hangs, repeated crashes, or unexpected data modifications, and check whether any internal hosts on the HFM segment show anomalous activity.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.