ZeroHour

CVE-2026-87224

niche

Authenticated Takeover Flaw in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87224 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Security component of Oracle Hyperion Financial Management, affecting only version 11.2.26.0.000. It is easily exploitable by a low-privileged (authenticated) attacker who has network access to the product over HTTP, and successful exploitation results in a complete takeover of Oracle Hyperion Financial Management with high impact on confidentiality, integrity, and availability. In practice, this means any user with even minimal valid credentials — such as a basic finance user or service account — could potentially escalate to full control of the application and its financial data. The flaw is delivered through Oracle's Critical Patch Update process and requires no user interaction or special conditions. There is no known public proof-of-concept, it is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-87224 to all Oracle Hyperion Financial Management 11.2.26.0.000 installations as soon as possible. In the interim, restrict HTTP access to the HFM web tier to trusted internal networks or VPN, and review low-privilege accounts for anomalous activity. Verify patch status across all EPM environments, including test and disaster-recovery instances that are often forgotten but reachable.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
nichelikely hundreds of internet-reachable instances out of a global installed base estimated in the low thousands of enterprise deployments — Oracle Hyperion Financial Management is on-premises enterprise EPM software used by mid-to-large finance organizations (typically thousands of deployments worldwide, not millions), only those on the specific 11.2.26.0.000 release are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.