ZeroHour

CVE-2026-87234

niche

Privilege Escalation and Full Data Access in Oracle Hyperion Financial Management 11.2

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

Oracle Hyperion Financial Management version 11.2.26.0.000 contains a flaw in its Security component that allows a low-privileged authenticated attacker with network access via HTTP to compromise the application. Successful exploitation gives the attacker unauthorized ability to create, delete, or modify critical data, as well as read access to all data accessible through Hyperion Financial Management. The vulnerability carries a CVSS 3.1 base score of 8.1 (high), driven by full confidentiality and integrity impact, though availability is not affected. Organizations running the affected 11.2.26.0.000 release — typically finance departments using Hyperion for consolidation and close processes — are at risk, especially if the application is reachable by broad sets of authenticated internal users. The flaw is not in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept or observed exploitation is known.

What to do: Apply the Oracle Critical Patch Update that remediates this issue for Hyperion Financial Management 11.2.26.0.000 as soon as patching windows allow. Restrict HTTP access to the HFM environment to only necessary finance and administrative users, and enforce least-privilege roles since the attack requires only a low-privileged account. Review audit logs for unexpected data modifications or access by low-privilege accounts as a detection measure.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)11.2.26.0.000
Estimated exposure
nichelow thousands of enterprise deployments worldwide (estimated) — Hyperion Financial Management is an enterprise performance management product deployed on-premises in finance departments of mid-to-large organizations, each installation serving one company, and such systems are rarely exposed to the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.