ZeroHour

CVE-2026-87221

moderate

Unauthenticated Data Disclosure in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87221 is a vulnerability in the Security component of Oracle Hyperion Financial Management affecting version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack results in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data, with high confidentiality impact and no integrity or availability impact (CVSS 3.1 base score 7.5). Organizations running the affected on-premises release, particularly those with HFM endpoints reachable over a network, are at risk of exposure of sensitive financial consolidation and reporting data. There is no evidence of in-the-wild exploitation, and no public proof-of-concept is known; the flaw is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that resolves CVE-2026-87221 to your Hyperion Financial Management 11.2.26.0.000 deployment as soon as it is available. Restrict HTTP access to HFM services so they are reachable only from trusted internal networks or VPN, and verify no instances are exposed to the internet. Review access and application logs around HFM data endpoints for unauthenticated requests or anomalous data retrieval that could indicate attempted exploitation.

Affected
Oracle Hyperion Financial Management11.2.26.0.000
Estimated exposure
moderateLikely a few thousand enterprise deployments globally, with plausibly only hundreds of HFM endpoints directly internet-exposed — Hyperion Financial Management is on-premises enterprise performance management software typically deployed by mid-to-large finance organizations in internal data centers, so installations number in the low thousands and public scan…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.