Sceawere

Vulnerability Detail

CVE-2026-87230UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Hyperion Financial Management Unauthenticated Compromise

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
11h ago
Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-09-15T20:19:11.513Z",
  "pubdate": "2026-09-15T20:19:11.513Z",
  "executiveSummary": "A critical vulnerability has been identified within the Oracle Hyperion Financial Management (HFM) product, specifically within the Security component.\nThe vulnerability allows an unauthenticated, remote attacker to gain unauthorized access and administrative control over sensitive financial data through HTTP-based exploitation.\nThis flaw is classified with a CVSS 3.1 Base Score of 10.0, indicating a maximum severity rating due to the ease of exploitation, lack of required privileges, and significant impact on data integrity and confidentiality.\nThe scope of this vulnerability extends beyond the HFM application itself (Scope: Changed), potentially impacting integrated systems within the broader Oracle ecosystem.\nThe flaw enables an attacker to perform unauthorized creation, deletion, or modification of critical business data, effectively compromising the entire underlying dataset.\nExploitation requires no user interaction and can be executed via standard network protocols, making it a high-priority risk for organizations utilizing HFM version 11.2.26.0.000.",
  "technicalDetails": "The vulnerability resides within the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. It manifests as a critical flaw in authentication or authorization handling, enabling remote, unauthenticated access via the HTTP protocol.\nThe root cause appears to be an architectural failure in how the Security component validates incoming service requests, allowing an attacker to bypass authentication mechanisms entirely.\nBecause the vulnerability involves a Scope Change (S:C), the compromise of the HFM component can lead to lateral movement or further unauthorized actions across related services connected to the same infrastructure. This suggests that the HFM security context is not sufficiently isolated, allowing a breach of this component to escalate impact to the broader enterprise application stack.\nThe attack flow involves the following sequence: (1) Reconnaissance of the target instance to confirm reachability of the vulnerable HTTP endpoint. (2) Transmission of a specifically crafted HTTP request designed to exploit the logic flaw in the Security component. (3) Successful bypass of authentication, granting the attacker the identity or privileges of a legitimate, potentially administrative, user. (4) Execution of unauthorized CRUD (Create, Read, Update, Delete) operations against the HFM database and application data structures.\nExploitation requires no specialized user interaction (UI:N). An attacker with simple network access to the HFM instance can trigger the payload. Given the complexity of HFM deployments, this vulnerability allows an actor to manipulate core financial records without being detected by standard application-layer logging if the attacker assumes administrative control.\nThe post-exploitation impact is severe, resulting in a total compromise of data integrity and confidentiality. An attacker may exfiltrate sensitive financial records, modify fiscal data, or inject malicious configurations that persist within the environment. The integrity impact ensures that business-critical information can be rendered unreliable, while the confidentiality impact ensures that proprietary financial data is fully accessible to unauthorized parties.\nThis vulnerability highlights a critical failure in the Security component's input validation and session integrity checks, which are fundamental to preventing unauthorized access in multi-tier, enterprise-grade financial systems."
}
CVE-2026-87230: Hyperion Financial Management Unauthenticated Compromise (CRITICAL Severity, CVSS: 10.0) | Sceawere