ZeroHour

CVE-2026-87227

moderate

Low-Privilege Takeover Flaw in Oracle Hyperion Financial Management 11.2 Security Component

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87227 is a vulnerability in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. An authenticated, low-privileged attacker with network access via HTTP can exploit the flaw with low complexity and no user interaction to fully compromise the application. A successful attack results in complete takeover of Oracle Hyperion Financial Management, with high impact on the confidentiality, integrity, and availability of financial data (CVSS 3.1 base score 8.8). Organizations running on-premises HFM 11.2.26.0.000 with HTTP-reachable services and low-privileged user accounts (e.g., general finance users) are affected. No public proof-of-concept is known and the flaw is not on CISA's KEV list, so exploitation is not currently observed in the wild.

What to do: Apply the Oracle Critical Patch Update that remedies this flaw to Hyperion Financial Management 11.2.26.0.000 as soon as it is available, prioritizing any instance reachable over HTTP. Restrict network access to Hyperion services (workspace, HFM web tier) to trusted VPN/internal ranges and enforce strong role-based access so low-privileged accounts are minimized. Review audit logs for anomalous privilege changes, unexpected account creation, or data access by low-privilege users that could indicate attempted exploitation.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
moderate≈2,000–5,000 enterprise installations worldwide (est.), of which only a few hundred are likely internet-exposed — Oracle Hyperion Financial Management is enterprise EPM software deployed on-premises mainly at large finance organizations, and public internet scan engines typically show only a few hundred exposed Hyperion endpoints since most instances…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.