CVE-2026-87229
nicheUnauthenticated Data Tampering in Oracle Hyperion Financial Management 11.2.26.0.0
CVE-2026-87229 is an easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management, affecting only version 11.2.26.0.000. An unauthenticated attacker with network access to the product over HTTP can trigger the flaw without any user interaction or privileges. A successful attack allows the attacker to create, delete, or modify critical data (or all data accessible to the product) and to read a subset of that data, yielding a CVSS 3.1 base score of 8.2 with high integrity and low confidentiality impact and no availability impact. Organizations running the affected on-premises version of this enterprise financial close/consolidation software are exposed, particularly if the web tier is reachable from untrusted networks. No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently known to be occurring in the wild.
What to do: Apply Oracle's latest Critical Patch Update to upgrade Oracle Hyperion Financial Management from 11.2.26.0.000 to a patched release as soon as it is available. In the interim, restrict HTTP access to the Hyperion Financial Management web tier so it is reachable only from trusted internal networks or over VPN, and place it behind an authenticating reverse proxy if possible. Review financial data and security configuration for unauthorized creation, modification, or deletion since the system went live on the affected version.
| Oracle Hyperion Financial Management (Oracle Hyperion) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.