A CVSS 9.1 vulnerability in the Security component of Oracle Hyperion Financial Management 11.2.26.0.000 lets a network-based attacker with high privileges take over the product, with a changed scope that may extend impact to resources beyond it.
What Is It
CVE-2026-87214 is a critical vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion, specifically in its Security component. Oracle describes the flaw as easily exploitable: an attacker with network access via HTTP and high privileges compromises the product, and a successful attack results in full takeover of Oracle Hyperion Financial Management. Because the scope is changed (S:C), the C:H/I:H/A:H ratings describe complete loss of confidentiality, integrity, and availability in the impacted component; which, under a changed scope, extends beyond the vulnerable component itself.
The vulnerability carries a CVSS 3.1 base score of 9.1 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, high privileges required, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact. The record was published by Oracle ([email protected]) on 2026-09-15 and is currently in "Received" status in NVD.
Why It Matters
The scope change is the key detail here. The S:C rating means a successful compromise is not necessarily contained to the vulnerable component; it can cross a security boundary into other resources, and Oracle warns that attacks "may significantly impact additional products." Combined with high impact across all three CIA dimensions and low attack complexity over HTTP, this is a full-takeover condition in a financial consolidation and reporting platform.
The mitigating factor is the privilege requirement: an attacker needs high privileges before exploiting this. That narrows the attack path to insiders, compromised administrative accounts, or a chained exploit that first obtains elevated access. It is a real constraint, not a reason to defer patching; administrative credential compromise is a routine step in intrusions against enterprise financial applications.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Hyperion Financial Management
- Component: Security
- Affected version: 11.2.26.0.000
No other versions are listed as affected in the supplied record, and no CPE entries have been assigned yet.
Patch Status
Oracle published this issue as part of its September 2026 security alert bundle. The single reference provided is Oracle's security alert page, which should be treated as the authoritative source for fixed versions and patch application guidance.
There is no CISA KEV entry for CVE-2026-87214 in the supplied data; active exploitation is not confirmed, and no federal required-action deadline applies at this time.