CVE-2026-87187: High severity Oracle Oracle Hyperion Financial Management vulnerability
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Deployments running Oracle Hyperion Financial Management version 11.2.26.0.000 are affected if an attacker can access the physical communication segment connected to the hardware hosting the product. The attack does not require an authenticated product account.
Does exploitation require user interaction or special conditions?
No user interaction is required, and the vulnerability has low attack complexity. The attacker must have adjacent-network access, meaning access to the relevant physical communication segment rather than general remote Internet access.
What is the potential impact of a successful attack?
A successful attack can result in takeover of Oracle Hyperion Financial Management. Confidentiality, integrity, and availability can all be affected at high impact.
What can be done if updating is not immediately possible?
Restrict access to the physical communication segment attached to the hardware running Oracle Hyperion Financial Management. Prioritize preventing unauthorized adjacent-network access because no authentication is required for exploitation.