CVE-2026-87241
nicheUnauthenticated Adjacent-Network Data Flaw in Oracle Hyperion Financial Management
Oracle Hyperion Financial Management 11.2.26.0.000 contains a vulnerability in its Security component that can be exploited by an unauthenticated attacker who can reach the network segment attached to the server running the product. The attack requires no privileges, no user interaction, and low complexity, meaning any device on the same LAN, VLAN, or VPN-connected segment as the HFM server is a potential launch point. A successful attack allows full compromise of data confidentiality and integrity — including unauthorized creation, deletion, or modification of critical financial data, plus unauthorized read access to all HFM-accessible data — though availability is not impacted. The affected population is limited to organizations running the on-premises 11.2.26.0.000 release of this enterprise financial close and consolidation product. There is no evidence of exploitation in the wild and no public proof of concept, but the low attack complexity and high data impact make patching a priority for exposed deployments.
What to do: Apply the Oracle Critical Patch Update that remediates this issue as soon as it is available for your 11.2.x deployment. Until patched, restrict network access to the HFM application tier with firewall rules and VLAN segmentation so only known finance/IT clients and admin workstations can reach the service ports, and treat VPN or jump-host access into that segment as part of the attack surface. Review HFM audit logs for unexpected data creation, modification, or deletion by unauthenticated or anomalous sources.
| Oracle Hyperion Financial Management (Oracle Hyperion) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.