ZeroHour

CVE-2026-87223

niche

Unauthenticated Data Manipulation and DoS in Oracle Hyperion Financial Management

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

Oracle Hyperion Financial Management 11.2.26.0.000 contains an easily exploitable flaw in its Security component that lets an unauthenticated attacker with network access via HTTP compromise the application. Successful attacks allow the attacker to create, delete, or modify critical data — or all data accessible to Hyperion Financial Management — and to cause a hang or repeatable crash, resulting in complete denial of service. The vulnerability carries a CVSS 3.1 base score of 9.1 (critical), with high integrity and availability impact but no confidentiality impact, meaning attackers can corrupt or destroy financial data rather than read it. Organizations running the affected on-premises release of this enterprise financial consolidation product are exposed, particularly any instance reachable over a network. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87223 to version 11.2.26.0.000 environments as soon as it is available. Restrict HTTP access to Hyperion Financial Management endpoints to trusted internal networks or VPN, and place a reverse proxy or WAF requiring authentication in front of any internet-reachable instance. Review audit logs for unexplained data creation, deletion, or modification and for repeated application crashes or hangs on financial consolidation data.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
nichelikely on the order of hundreds to a few thousand enterprise deployments globally; internet-exposed subset unknown — Oracle Hyperion Financial Management is niche on-premises financial consolidation software used mainly by large corporate finance departments and is typically deployed on internal networks, with no public active-install or scan counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.