Oracle has disclosed a critical vulnerability in the Security component of Oracle Hyperion Financial Management 11.2.26.0.000 that allows a network-based attacker with high privileges to take over the product and impact adjacent systems.
What Is It
CVE-2026-87189 is a vulnerability in the Security component of Oracle Hyperion Financial Management, part of the Oracle Hyperion product family. Per the CVSS metrics, it is a low-complexity flaw that lets a high-privileged attacker with network access compromise the product. Successful exploitation results in full takeover of Oracle Hyperion Financial Management.
It carries a CVSS 3.1 base score of 9.1 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, high privileges required, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact.
Why It Matters
The defining detail here is the scope change. The vulnerability lives in Hyperion Financial Management, but the changed-scope metric means attacks may significantly impact additional products beyond the vulnerable component. That moves this out of the category of a contained application bug and into something that can be used as a pivot beyond the Hyperion boundary.
The mitigating factor is the privilege requirement: an attacker needs high privileges to begin with. That holds the exploitability subscore down to 2.3. What drives the 9.1 rating is the impact subscore of 6.05, which is what a changed-scope vector with high confidentiality, integrity, and availability impact produces under CVSS 3.1. In practice this is an insider-or-post-compromise escalation path with full takeover at the end of it.
As of this writing, CVE-2026-87189 does not appear in the CISA Known Exploited Vulnerabilities catalog, so no federal remediation deadline applies to it under BOD 22-01. Absence from the catalog is not evidence that exploitation is not occurring, only that CISA has not confirmed it, and the catalog should be rechecked, since entries are added as evidence emerges.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Hyperion Financial Management (Oracle Hyperion), component: Security
- Affected version: 11.2.26.0.000
No other versions or products are listed as affected in the NVD record.
Patch Status
The CVE was published on 2026-09-15 and its NVD status is currently Received, meaning the record has not yet completed NVD analysis. The single reference provided is Oracle's Critical Patch Update advisory for the September 2026 cycle, which is the authoritative source for fix availability and applicable patches. Administrators running 11.2.26.0.000 should consult that advisory directly and apply the corresponding Oracle update.
Sources
- NVD, CVE-2026-87189: https://nvd.nist.gov/vuln/detail/CVE-2026-87189
- Oracle Critical Patch Update Advisory (September 2026): https://www.oracle.com/security-alerts/cpusep2026.html
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog