A CVE record attributed to Oracle describes a CVSS 9.6 flaw in the Security component of Oracle Hyperion Financial Management 11.2.26.0.000 that, according to the advisory data, would let an unauthenticated attacker on the adjacent network segment fully take over the product.
What Is It
Per the CVE record, the vulnerability sits in the Security component of Oracle Hyperion Financial Management, part of the Oracle Hyperion product family. The advisory data characterizes it as an easily exploitable flaw: an unauthenticated attacker with access to the physical communication segment attached to the hardware where Hyperion Financial Management runs is said to be able to compromise the product outright, with successful exploitation resulting in complete takeover. These characterizations come from the vendor-supplied advisory text and have not yet been independently corroborated.
The record carries a CVSS 3.1 base score of 9.6 (Critical) with the vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, adjacent-network attack vector, low complexity, no privileges, no user interaction, and high impact to confidentiality, integrity, and availability.
Why It Matters
Three things make this one worth prioritizing. First, no authentication and no user interaction are required; the only barrier is network position. Second, the scope is changed, meaning the advisory indicates attacks may significantly impact additional products beyond Hyperion Financial Management itself. Third, Hyperion Financial Management is a financial consolidation and close platform, so a takeover puts sensitive financial reporting data and its integrity directly at risk.
The adjacent-network requirement (AV:A) limits exposure to attackers who already have a foothold on the same communication segment, but that is a realistic post-compromise position in most enterprise environments and should not be treated as a mitigating control on its own.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Hyperion Financial Management
- Component: Security
- Affected version: 11.2.26.0.000
This is the only supported version listed as affected in the advisory data.
Patch Status
The CVE record was published 2026-09-15 and carries NVD status "Received," meaning NVD enrichment analysis is not yet complete. A single Oracle reference URL is supplied with the record, and it is the only remediation pointer currently attached to the CVE. That URL does not follow Oracle's usual naming convention for Critical Patch Updates or Security Alerts, so administrators should not assume it resolves to a live advisory; treat it as a lead and confirm the correct advisory through Oracle's security alerts index or through Oracle Support before planning remediation. Organizations running 11.2.26.0.000 should track Oracle's published guidance for this CVE and apply the corresponding fix once identified.
No CISA KEV entry accompanies this CVE, so there is no confirmed evidence of active exploitation and no KEV-mandated remediation deadline at this time.
Sources
- NVD, CVE-2026-87186: https://nvd.nist.gov/vuln/detail/CVE-2026-87186
- Oracle reference supplied with the CVE record (verify before relying on it): https://www.oracle.com/security-alerts/cspusep2026.html