CVE-2026-87221
moderateUnauthenticated Data Disclosure in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87221 is a vulnerability in the Security component of Oracle Hyperion Financial Management affecting version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack results in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data, with high confidentiality impact and no integrity or availability impact (CVSS 3.1 base score 7.5). Organizations running the affected on-premises release, particularly those with HFM endpoints reachable over a network, are at risk of exposure of sensitive financial consolidation and reporting data. There is no evidence of in-the-wild exploitation, and no public proof-of-concept is known; the flaw is not on the CISA Known Exploited Vulnerabilities catalog.
What to do: Apply the Oracle Critical Patch Update that resolves CVE-2026-87221 to your Hyperion Financial Management 11.2.26.0.000 deployment as soon as it is available. Restrict HTTP access to HFM services so they are reachable only from trusted internal networks or VPN, and verify no instances are exposed to the internet. Review access and application logs around HFM data endpoints for unauthenticated requests or anomalous data retrieval that could indicate attempted exploitation.
| Oracle Hyperion Financial Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.