CVE-2026-87232
nicheUnauthenticated Data Access and Tampering Flaw in Oracle Hyperion Financial Management
A vulnerability in the Security component of Oracle Hyperion Financial Management (HFM) version 11.2.26.0.000 allows an unauthenticated attacker to compromise the application, provided the attacker has access to the physical communication segment (adjacent/local network) attached to the server where HFM executes. Exploitation requires no privileges, no user interaction, and is rated as easy (CVSS 3.1 base score 8.1, vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). A successful attack lets the attacker gain unauthorized read access to all HFM-accessible data and unauthorized ability to create, delete, or modify critical data, with no direct impact on availability. Organizations running the affected on-premises release are at risk primarily from malicious insiders or external attackers who have already gained a foothold on the same network segment as the HFM server. No public proof of concept is known, the CVE is not in CISA's KEV catalog, and no exploitation in the wild has been reported.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-87232 and move off HFM 11.2.26.0.000 to a patched release. Because the attack path is unauthenticated but adjacent-network only, segment HFM servers onto a tightly restricted VLAN and permit only known application, database, and administrative hosts to reach them. Audit HFM security configuration (users, roles, permissions) and financial application data for unauthorized changes or access.
| Oracle Hyperion Financial Management (Oracle Hyperion) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.