ZeroHour

CVE-2026-87230

moderate

Unauthenticated Critical Flaw in Oracle Hyperion Financial Management Security Component

CVSS 3.1
10.0 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-87230 is a flaw in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. Successful attacks allow unauthorized creation, deletion, or modification of critical data — or all data accessible to Oracle Hyperion Financial Management — as well as unauthorized read access to that data, and because of a scope change, the impact can extend beyond Hyperion Financial Management to additional products. The vulnerability carries a maximum CVSS 3.1 base score of 10.0, driven by high confidentiality and integrity impacts. No public proof of concept is known, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported to date.

What to do: Apply the Oracle patch for this issue as soon as it is available via Oracle's Critical Patch Update for Hyperion 11.2.x, since 11.2.26.0.000 is the only listed affected version. Until patched, restrict network access to Hyperion Financial Management HTTP endpoints — remove internet exposure and place the service behind a VPN or allow-listed reverse proxy — and monitor authentication and Security component logs for unauthenticated access attempts. Verify that you are not running the affected 11.2.26.0.000 build on any production or DR instance.

Affected
Oracle Hyperion Financial Management11.2.26.0.000
Estimated exposure
moderatelikely on the order of a few thousand installations (low thousands of internet-reachable instances; unclear how many more exist on internal networks) — Oracle Hyperion Financial Management is enterprise EPM software deployed primarily at mid-size and large finance organizations — a customer base measured in thousands rather than millions — and public internet scans typically show only low…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.