CVE-2026-87219: High severity Oracle Oracle Hyperion Financial Management vulnerability
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
Can an attacker exploit this remotely or without credentials?
No. Exploitation requires a low-privileged attacker to have a logon to the infrastructure where Oracle Hyperion Financial Management runs; the CVSS vector identifies the attack vector as local and privileges as low.
Which version is identified as affected?
The affected supported version identified is 11.2.26.0.000. No other versions are specified in the available data.
Could exploitation affect systems or data outside the vulnerable component?
Yes. The vulnerability has a scope change, and successful attacks may significantly affect additional products. An attacker may obtain access to data accessible to Oracle Hyperion Financial Management.
Does the reported impact include service availability disruption?
No availability impact is indicated in the supplied CVSS vector, which sets Availability to None. The stated impacts are high confidentiality and integrity impact, including unauthorized access to, creation of, deletion of, or modification of data.