CVE-2026-87197: High severity Oracle Oracle Hyperion Financial Management vulnerability
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle Hyperion Financial Management over HTTP so unauthenticated attackers cannot reach the vulnerable component.
Event History
Frequently Asked Questions
Which deployments are affected?
Oracle Hyperion Financial Management version 11.2.26.0.000 is identified as affected. The issue is in the product's Security component.
Does exploitation require an authenticated account or user interaction?
No. An unauthenticated attacker can exploit the vulnerability over HTTP with network access, and no user interaction is required.
What access could an attacker gain?
Successful exploitation can expose critical data or all data accessible to Oracle Hyperion Financial Management. An attacker may also be able to update, insert, or delete some accessible data.
Is this exploitable remotely?
Yes. The CVSS vector identifies network attack access, and the vulnerability is reachable via HTTP.