CVE-2026-87249
nicheUnauthenticated Data-Tampering Flaw in Oracle Hyperion Financial Management
A vulnerability in the Security component of Oracle Hyperion Financial Management (HFM) 11.2.26.0.000 allows an unauthenticated attacker with network access via HTTP to compromise the application. Exploitation is technically easy but requires human interaction, meaning a legitimate user must be tricked into performing an action (a CSRF-style attack pattern). A successful attack gives the attacker unauthorized ability to create, delete, or modify critical data or all HFM-accessible data, and to cause a partial denial of service; confidentiality is not impacted. Organizations running the affected on-premises release are at risk, especially where HFM web endpoints are reachable from untrusted or broad internal networks. No public proof of concept or known in-the-wild exploitation has been reported to date.
What to do: Apply the Oracle Critical Patch Update that remediates this CVE as soon as it is available and confirm your HFM build, since 11.2.26.0.000 is explicitly listed as affected. Restrict HTTP access to HFM endpoints so only trusted internal networks or VPN-authenticated users can reach them, as the flaw is exploitable without credentials. Because successful attacks require user interaction, brief finance users against clicking untrusted links or acting on unexpected prompts during HFM sessions, and audit HFM data for unauthorized modifications or deletions.
| Oracle Hyperion Financial Management | 11.2.26.0.000 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.