ZeroHour

CVE-2026-87240

moderate

Local Privilege Escalation in Oracle Hyperion Financial Management 11.2.26 (Security Component)

CVSS 3.1
7.0 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87240 is a difficult-to-exploit privilege escalation vulnerability in the Security component of Oracle Hyperion Financial Management, affecting version 11.2.26.0.000. A low-privileged attacker who already has the ability to log on to the operating system or infrastructure where Hyperion Financial Management runs can leverage the flaw to fully compromise the application, achieving high impacts to confidentiality, integrity, and availability (CVSS 3.1 base score 7.0). Because the attack vector is local and requires an existing low-privilege foothold on the server, the risk is concentrated on authorized users, service accounts, or attackers who have already gained local access. Successful exploitation results in complete takeover of the Hyperion Financial Management instance, which typically holds sensitive consolidated financial data. No public proof-of-concept exists and the vulnerability is not in the CISA Known Exploited Vulnerabilities catalog, so there is no indication of active exploitation.

What to do: Apply the Oracle Critical Patch Update that addresses this issue to all Hyperion Financial Management 11.2.26.0.000 deployments as soon as it is available. Restrict local OS-level logon rights on HFM servers to a minimal set of administrators and service accounts, and audit existing local accounts for unauthorized creation or privilege changes. Monitor authentication and process-escalation activity on Hyperion infrastructure for signs of post-compromise behavior.

Affected
Oracle Hyperion Financial Management11.2.26.0.000
Estimated exposure
moderateLow thousands of enterprise installations worldwide (estimated) — Hyperion Financial Management is on-premises enterprise performance management software concentrated in large corporate finance organizations, and no public active-install counts or internet-scan data exist, so this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.