CVE-2026-87179

8.8

Oracle · Hyperion Financial Management

A security vulnerability in Oracle Hyperion Financial Management allows a low privileged, network-based attacker to gain full control of the application via HTTP.

Executive summary

A high-severity security flaw in Oracle Hyperion Financial Management version 11.2.26.0.000 permits unauthorized system takeover by authenticated attackers.

Vulnerability

This is a security-related vulnerability within the component architecture of Hyperion Financial Management. It allows an attacker with low-level privileges and network access to send crafted HTTP requests to trigger a full system takeover.

Business impact

The ability for an attacker to achieve a complete takeover of financial management software poses a catastrophic risk to organizational data integrity and confidentiality. Given the CVSS score of 8.8, this vulnerability is classified as High severity and could lead to unauthorized access to sensitive financial records, manipulation of fiscal data, and significant operational disruption.

Remediation

Immediate Action: Review the latest security alerts from Oracle at the provided reference link to identify and apply the necessary patches or configuration changes for version 11.2.26.0.000.

Proactive Monitoring: Monitor network access logs for suspicious HTTP requests targeting the Hyperion security component and audit user activity for anomalous behavior originating from low-privileged accounts.

Compensating Controls: Deploy Web Application Firewall (WAF) rules to inspect incoming HTTP traffic for malicious patterns associated with unauthorized administrative command execution until a permanent patch is verified and applied.

Exploitation status

Public Exploit Available: exploit_available (unknown)

Analyst recommendation

Due to the potential for total system compromise, organizations running Oracle Hyperion Financial Management 11.2.26.0.000 should prioritize this issue in their immediate patching cycle. Security teams should verify their environment for the affected version and apply vendor-supplied updates as soon as they become available to prevent unauthorized access and data manipulation.

More Oracle CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources