CVE-2026-87223
nicheUnauthenticated Data Manipulation and DoS in Oracle Hyperion Financial Management
Oracle Hyperion Financial Management 11.2.26.0.000 contains an easily exploitable flaw in its Security component that lets an unauthenticated attacker with network access via HTTP compromise the application. Successful attacks allow the attacker to create, delete, or modify critical data — or all data accessible to Hyperion Financial Management — and to cause a hang or repeatable crash, resulting in complete denial of service. The vulnerability carries a CVSS 3.1 base score of 9.1 (critical), with high integrity and availability impact but no confidentiality impact, meaning attackers can corrupt or destroy financial data rather than read it. Organizations running the affected on-premises release of this enterprise financial consolidation product are exposed, particularly any instance reachable over a network. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87223 to version 11.2.26.0.000 environments as soon as it is available. Restrict HTTP access to Hyperion Financial Management endpoints to trusted internal networks or VPN, and place a reverse proxy or WAF requiring authentication in front of any internet-reachable instance. Review audit logs for unexplained data creation, deletion, or modification and for repeated application crashes or hangs on financial consolidation data.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.