CVE-2026-87236
moderateAuthenticated Data Exposure and Partial DoS in Oracle Hyperion Financial Management
A high-severity flaw (CVSS 7.1) in the Security component of Oracle Hyperion Financial Management allows a low-privileged authenticated attacker with HTTP network access to the product to access data they should not be entitled to see. Successful exploitation can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data, and can enable a partial denial of service against the application. The vulnerability affects the supported version 11.2.26.0.000 and is described by Oracle as easily exploitable, requiring only a low-privileged account and no user interaction. Impacts are limited to confidentiality and availability; integrity is not affected. No public proof of concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently known to be occurring.
What to do: Apply the Oracle Critical Patch Update that remediates this issue to move off affected version 11.2.26.0.000. Restrict HTTP access to Hyperion Financial Management endpoints to trusted networks, VPN users, or an authenticated reverse proxy, and enforce least-privilege role assignments. Audit access logs for low-privileged accounts exhibiting unusual data-access patterns or activity consistent with denial-of-service attempts.
| Oracle Hyperion Financial Management (component: Security) | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.