CVE-2026-87187

Oracle · Hyperion Financial Management

An unauthenticated vulnerability in Oracle Hyperion Financial Management allows an attacker with local network access to achieve a full system takeover.

Executive summary

An unauthenticated security vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000 permits unauthorized system takeover by attackers with local network access.

Vulnerability

The vulnerability exists within the security component of the software and allows an unauthenticated attacker to compromise the application. The attack requires the adversary to have access to the physical communication segment attached to the hardware where the application is executing.

Business impact

The potential for a complete system takeover represents a critical risk to business operations, as it grants attackers full control over sensitive financial data and administrative functions. Given the CVSS score of 8.8, this vulnerability is classified as High severity, indicating that unauthorized access could lead to severe confidentiality, integrity, and availability breaches. Organizations relying on this platform for financial reporting must prioritize mitigation to prevent catastrophic data loss or manipulation.

Remediation

Immediate Action: Consult the official Oracle security advisory at https://www.oracle.com/security-alerts/cspusep2026.html to identify and apply the necessary security updates or configuration changes.

Proactive Monitoring: Monitor network traffic for unusual activity originating from within the local communication segment and review administrative access logs for unauthorized sessions.

Compensating Controls: Restrict physical and logical network access to the hardware hosting the Hyperion Financial Management instance to authorized personnel only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the severity of the impact and the potential for complete system compromise, administrators should treat this vulnerability with high urgency. Immediately restrict network access to the affected hardware and implement the vendor recommended patches as soon as they become available. Consistent monitoring of the affected environment is essential until the system is fully remediated.

More Oracle CVEs all →

History

  1. Collected by CVE Brief via github
  2. Held for re-check analysis graded thin
  3. Analyst report written

Sources