ZeroHour

CVE-2026-87233

niche

Privileged Data-Access Flaw in Oracle Hyperion Financial Management Security Component

CVSS 3.1
7.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87233 is a vulnerability in the Security component of Oracle Hyperion Financial Management affecting version 11.2.26.0.000. It is easily exploitable by an attacker who already holds high privileges and has network access via HTTP to the Hyperion Financial Management server. A successful attack can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data, as well as a partial denial of service; because the scope changes, attacks may also significantly impact additional products beyond Hyperion Financial Management itself. The vulnerability carries a CVSS 3.1 base score of 7.6 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L). There is no known public proof of concept and no evidence of in-the-wild exploitation as of this writing.

What to do: If you run Oracle Hyperion Financial Management 11.2.26.0.000, apply the Oracle Critical Patch Update that addresses this CVE as soon as it is released and verify your version with Oracle support. Restrict HTTP network access to Hyperion Financial Management services so only trusted finance/IT users and networks can reach them, and enforce least-privilege on all high-privileged HFM accounts. Review audit logs for unusual data access or degradation from privileged accounts, since exploitation requires an already-high-privileged attacker.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)
Estimated exposure
nichelikely low thousands of enterprise on-premises deployments worldwide, with only hundreds to low thousands of internet-exposed instances — Oracle Hyperion Financial Management is on-premises enterprise performance management software used mainly by large finance organizations rather than a mass-market product, and public internet scans historically show a comparatively small…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.