CVE-2026-87224
nicheAuthenticated Takeover Flaw in Oracle Hyperion Financial Management 11.2.26
CVE-2026-87224 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Security component of Oracle Hyperion Financial Management, affecting only version 11.2.26.0.000. It is easily exploitable by a low-privileged (authenticated) attacker who has network access to the product over HTTP, and successful exploitation results in a complete takeover of Oracle Hyperion Financial Management with high impact on confidentiality, integrity, and availability. In practice, this means any user with even minimal valid credentials — such as a basic finance user or service account — could potentially escalate to full control of the application and its financial data. The flaw is delivered through Oracle's Critical Patch Update process and requires no user interaction or special conditions. There is no known public proof-of-concept, it is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-87224 to all Oracle Hyperion Financial Management 11.2.26.0.000 installations as soon as possible. In the interim, restrict HTTP access to the HFM web tier to trusted internal networks or VPN, and review low-privilege accounts for anomalous activity. Verify patch status across all EPM environments, including test and disaster-recovery instances that are often forgotten but reachable.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.