ZeroHour

CVE-2026-87229

niche

Unauthenticated Data Tampering in Oracle Hyperion Financial Management 11.2.26.0.0

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87229 is an easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management, affecting only version 11.2.26.0.000. An unauthenticated attacker with network access to the product over HTTP can trigger the flaw without any user interaction or privileges. A successful attack allows the attacker to create, delete, or modify critical data (or all data accessible to the product) and to read a subset of that data, yielding a CVSS 3.1 base score of 8.2 with high integrity and low confidentiality impact and no availability impact. Organizations running the affected on-premises version of this enterprise financial close/consolidation software are exposed, particularly if the web tier is reachable from untrusted networks. No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently known to be occurring in the wild.

What to do: Apply Oracle's latest Critical Patch Update to upgrade Oracle Hyperion Financial Management from 11.2.26.0.000 to a patched release as soon as it is available. In the interim, restrict HTTP access to the Hyperion Financial Management web tier so it is reachable only from trusted internal networks or over VPN, and place it behind an authenticating reverse proxy if possible. Review financial data and security configuration for unauthorized creation, modification, or deletion since the system went live on the affected version.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
nichelikely hundreds to low thousands of internet-reachable deployments worldwide — Oracle Hyperion Financial Management is on-premises enterprise EPM software deployed by a relatively small base of large finance organizations, and public scan engines typically show only low thousands of exposed Hyperion web endpoints, of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.