ZeroHour

Vulnerabilities

2,168 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-87230
Unauthenticated Critical Flaw in Oracle Hyperion Financial Management Security Component

CVE-2026-87230 is a flaw in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. Successful attacks allow unauthorized creation, deletion, or modification of critical data — or all data accessible to Oracle Hyperion Financial Management — as well as unauthorized read access to that data, and because of a scope change, the impact can extend beyond Hyperion Financial Management to additional products. The vulnerability carries a maximum CVSS 3.1 base score of 10.0, driven by high confidentiality and integrity impacts. No public proof of concept is known, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported to date.

Do: Apply the Oracle patch for this issue as soon as it is available via Oracle's Critical Patch Update for Hyperion 11.2.x, since 11.2.26.0.000 is the only listed affected version. Until patched, restrict network access to Hyperion Financial Management HTTP endpoints — remove internet exposure and place the service behind a VPN or allow-listed reverse proxy — and monitor authentication and Security component logs for unauthenticated access attempts. Verify that you are not running the affected 11.2.26.0.000 build on any production or DR instance.

10.0
group max
  • Oracle Hyperion Financial Management 11.2.26.0.000
moderatelikely on the order of a few thousand installations (low thousands of internet-reachable instances; unclear how many more exist on internal networks)