ZeroHour

CVE-2026-87235

niche

Unauthenticated SSH Data Access Flaw in Oracle Hyperion Financial Management 11.2.26

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87235 is a difficult-to-exploit, unauthenticated vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000, reachable by a network attacker over SSH. A successful attack requires no privileges or user interaction (CVSS 3.1: 7.4, AV:N/AC:H/PR:N/UI:N) and allows the attacker to gain unauthorized creation, deletion, or modification access to critical data — up to all HFM-accessible data — as well as unauthorized read access to that data, with high confidentiality and integrity impact and no availability impact. The affected population is organizations running the supported on-premises release 11.2.26.0.000 of Hyperion Financial Management, typically large enterprise finance departments. No public proof-of-concept is known, the issue is not on the CISA Known Exploited Vulnerabilities list, and there are no reports of in-the-wild exploitation.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87235 and move affected 11.2.26.0.000 systems to the patched release. Restrict SSH access on Hyperion Financial Management hosts to trusted administrative networks or a management bastion, since the attack vector is unauthenticated network access via SSH. Review HFM application and financial-consolidation data for unauthorized creation, modification, or deletion around the period the vulnerable version was in service.

Affected
Oracle Hyperion Financial Management (Oracle Hyperion)
Estimated exposure
nichelikely low thousands of enterprise HFM deployments globally, with only a small fraction internet-exposed — Hyperion Financial Management is on-premises enterprise EPM software licensed mainly to large finance organizations, so deployment counts are far below mass-market software and instances are typically kept on internal networks; precise…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.