ZeroHour

CVE-2026-87249

niche

Unauthenticated Data-Tampering Flaw in Oracle Hyperion Financial Management

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

A vulnerability in the Security component of Oracle Hyperion Financial Management (HFM) 11.2.26.0.000 allows an unauthenticated attacker with network access via HTTP to compromise the application. Exploitation is technically easy but requires human interaction, meaning a legitimate user must be tricked into performing an action (a CSRF-style attack pattern). A successful attack gives the attacker unauthorized ability to create, delete, or modify critical data or all HFM-accessible data, and to cause a partial denial of service; confidentiality is not impacted. Organizations running the affected on-premises release are at risk, especially where HFM web endpoints are reachable from untrusted or broad internal networks. No public proof of concept or known in-the-wild exploitation has been reported to date.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE as soon as it is available and confirm your HFM build, since 11.2.26.0.000 is explicitly listed as affected. Restrict HTTP access to HFM endpoints so only trusted internal networks or VPN-authenticated users can reach them, as the flaw is exploitable without credentials. Because successful attacks require user interaction, brief finance users against clicking untrusted links or acting on unexpected prompts during HFM sessions, and audit HFM data for unauthorized modifications or deletions.

Affected
Oracle Hyperion Financial Management11.2.26.0.000
Estimated exposure
nichelikely hundreds to a few thousand enterprise deployments worldwide; only those on release 11.2.26.0.000 are affected — Oracle Hyperion HFM is on-premises enterprise financial-close software with a limited customer base and no public install counts, and the affected version is a single supported release, so the exposed population is a small subset of an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.