Oracle has disclosed a critical, remotely exploitable vulnerability in the Security component of Oracle Hyperion Financial Management 11.2.26.0.000 that lets an unauthenticated attacker tamper with or destroy financial data and crash the application outright.
What Is It
CVE-2026-87223 is a vulnerability in the Security component of Oracle Hyperion Financial Management, part of the Oracle Hyperion product family. Oracle describes it as easily exploitable: an unauthenticated attacker with network access over HTTP can compromise the product without any user interaction or prior privileges.
Successful exploitation allows unauthorized creation, deletion, or modification of critical data, or of all data accessible to Hyperion Financial Management, as well as the ability to force a hang or a frequently repeatable crash, a complete denial of service.
Why It Matters
The CVSS 3.1 base score is 9.1 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H. That breaks down to network attack vector, low attack complexity, no privileges required, and no user interaction; the maximum exploitability subscore of 3.9.
The impact profile is unusual: confidentiality impact is rated NONE, while both integrity and availability are HIGH. This is not a data-theft bug. It is a data-integrity and uptime bug against a financial consolidation and reporting platform, where silently altered or deleted records carry consequences well beyond the application itself.
CVE-2026-87223 does not appear in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-15, so there is no confirmation of active exploitation and no BOD 22-01 remediation deadline for federal civilian agencies at this time. Defenders should treat the KEV catalog as the authoritative check here, and re-check it as the record matures.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Hyperion Financial Management (component: Security)
- Affected version: 11.2.26.0.000
Oracle lists 11.2.26.0.000 as the supported version affected. The NVD record as it currently stands does not appear to enumerate other versions or CPE configurations, though the entry is still pre-analysis and the affected-version data may expand.
Patch Status
The CVE was published on 2026-09-15 with an NVD status of "Received," meaning the record has not yet completed NVD analysis. The sole reference is Oracle's security alert page for September 2026, which is the authoritative source for fix availability and applicable patch levels. As of this writing, neither the NVD record nor the linked Oracle alert appears to state a specific required action or remediation date; administrators running 11.2.26.0.000 should consult the Oracle advisory directly, since patch guidance and fixed-version details may be published or updated there after this record was reviewed.
Sources
- Oracle Security Alert (September 2026), https://www.oracle.com/security-alerts/cspusep2026.html
- NVD, CVE-2026-87223, https://nvd.nist.gov/vuln/detail/CVE-2026-87223
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog