CVE-2026-87172
9.9Oracle · Hyperion Financial Management
A critical security vulnerability in Oracle Hyperion Financial Management allows low privileged attackers to achieve a full system takeover via network-based HTTP requests.
Executive summary
A critical vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000 allows authenticated attackers to gain complete control of the system, creating significant risk of compromise.
Vulnerability
This is a security-related flaw that permits a low privileged attacker with network access to execute unauthorized actions, resulting in a full system takeover and potential cross-product impact due to scope change.
Business impact
The exploitation of this vulnerability carries a CVSS base score of 9.9, reflecting its critical severity and potential for total compromise of confidentiality, integrity, and availability. Successful attacks enable an adversary to gain administrative control over the financial management environment, which could lead to unauthorized data access, manipulation of critical financial records, and potential lateral movement into integrated enterprise systems.
Remediation
Immediate Action: Organizations should review the Oracle Security Alerts for September 2026 and apply the latest available updates or patches provided by Oracle to address this flaw.
Proactive Monitoring: Security teams should monitor network access logs for anomalous HTTP traffic targeting the Hyperion security component and audit logs for unauthorized privilege escalation attempts.
Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall to restrict access to the affected service, ensuring only authorized users can interact with the application interface.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the critical nature of this vulnerability and the potential for complete system compromise, administrators must prioritize the assessment of their Hyperion environment. Apply the vendor-supplied security updates as soon as they become available to mitigate the risk of unauthorized access and maintain the integrity of financial data.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
- Oracle Advisory Vendor advisory