Cyber & AI intelligence
Wasteland.
Briefs indexed2663
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-87172 2026-09-15

CVE-2026-87172: Critical Oracle Hyperion Financial Management Flaw Allows Full Takeover

"Oracle has disclosed a CVSS 9.9 vulnerability in the Security component of Oracle Hyperion Financial Management 11.2.26.0.000 that lets a low-privileged network attacker take over the product and, per Oracle, may…"

Oracle has disclosed a CVSS 9.9 vulnerability in the Security component of Oracle Hyperion Financial Management 11.2.26.0.000 that lets a low-privileged network attacker take over the product and, per Oracle, may significantly impact additional products.

What Is It

CVE-2026-87172 is a vulnerability in the Security component of Oracle Hyperion Financial Management, part of the Oracle Hyperion product family. Oracle describes it as easily exploitable: an attacker with low privileges and network access over HTTP can compromise the product without any user interaction. Successful exploitation results in complete takeover of Oracle Hyperion Financial Management.

The CVSS 3.1 base score is 9.9 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, high impact to confidentiality, integrity, and availability. The record was published 2026-09-15 with Oracle as the assigning CNA, and currently carries NVD status "Received."

Why It Matters

Three factors stack here. First, the scope is changed (S:C): Oracle warns that while the flaw lives in Hyperion Financial Management, attacks "may significantly impact additional products." The scope-change metric indicates the blast radius is not necessarily limited to the vulnerable component itself.

Second, the bar to exploit is low. Attack complexity is LOW, no user interaction is required, and the attacker needs only low privileges; meaning any authenticated account with minimal rights on a network-reachable instance is sufficient.

Third, the affected component is Security itself, in a financial consolidation and reporting platform that by design holds sensitive corporate financial data.

What's Vulnerable

No other versions are listed as affected in the supplied NVD record, and no CPE match data has been published yet.

Patch Status

The NVD record carries a reference to an Oracle security-alerts page (cspusep2026.html), but that filename does not match Oracle's published advisory URL conventions and the page could not be confirmed as a live Oracle advisory. Oracle's Critical Patch Updates ship on a fixed quarterly schedule, January, April, July, and October, so a mid-September release would have to be an out-of-cycle Security Alert rather than a CPU. Treat the availability and identity of a fix as unconfirmed until Oracle's advisory is located directly on the vendor's Security Alerts index.

No CISA KEV entry exists for CVE-2026-87172; there is no confirmation of active exploitation in the wild, and no KEV-mandated remediation deadline applies.

Given the 9.9 score and the scope-change warning, operators running 11.2.26.0.000 should track Oracle's Security Alerts and CPU announcements for the applicable patch, and restrict network exposure of Hyperion Financial Management instances in the interim.

Sources