ZeroHour

CVE-2026-87228

moderate

Unauthenticated Data Access Flaw in Oracle Hyperion Financial Management 11.2

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

A high-severity (CVSS 8.2) vulnerability in the Security component of Oracle Hyperion Financial Management allows an unauthenticated remote attacker with network access via HTTP to compromise the application. The flaw affects supported version 11.2.26.0.000 and is rated easily exploitable, requiring no privileges, credentials, or user interaction. Successful exploitation can result in unauthorized read access to critical data — up to complete access to all data reachable by Hyperion Financial Management — as well as unauthorized insert, update, or delete access to some of that data; availability is not impacted. Organizations running the affected on-premises release are exposed wherever the service is network-reachable, with the highest risk to any internet-facing deployments. No public proof of concept is known, the CVE is not on CISA's KEV list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87228 to Hyperion Financial Management 11.2.26.0.000 as soon as it is available for your release. Until patched, restrict HTTP access to Hyperion Financial Management servers to trusted internal networks or VPN and monitor for unauthenticated requests targeting the Security component. Review HFM application data and audit logs for signs of unexpected reads or unauthorized inserts, updates, or deletes.

Affected
Oracle Hyperion Financial Management11.2.26.0.000
Estimated exposure
moderatelow thousands of enterprise installations worldwide; internet-exposed subset likely only in the hundreds (estimate) — Oracle Hyperion Financial Management is on-premises enterprise EPM software typically deployed inside corporate networks for financial close and consolidation, and public scan engines show relatively few internet-exposed Hyperion…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.