PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87174 Oracle Corporation CVE debrief

A high-severity vulnerability exists in Oracle Hyperion Financial Management 11.2.26.0.000. An unauthenticated attacker with network access via TCP can exploit this vulnerability to gain unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data, as well as unauthorized update, insert, or delete access to some of Oracle Hyperion Financial Management accessible data.

Vendor
Oracle Corporation
Product
Oracle Hyperion Financial Management
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-18
Advisory published
2026-09-15
Advisory updated
2026-09-18

Who should care

Defenders responsible for Oracle Hyperion Financial Management deployments, security teams, vulnerability management teams, and operators of affected platforms should assess exposure and potential impacts. This includes IT administrators, security analysts, and compliance officers who need to verify exposure, assess risks, and implement necessary mitigations or patches.

Why it matters

Defenders should prioritize verifying exposure and assessing potential data access and integrity impacts due to a high-severity vulnerability in Oracle Hyperion Financial Management 11.2.26.0.000.

  • Potential unauthorized data access
  • Potential data integrity impacts
  • Need for verification of exposure and remediation

Technical summary

The vulnerability has a CVSS score of 8.2 and affects Oracle Hyperion Financial Management 11.2.26.0.000. An unauthenticated attacker with network access via TCP can exploit this vulnerability to gain unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data, as well as unauthorized update, insert, or delete access to some of Oracle Hyperion Financial Management accessible data.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential data access and integrity impacts.

Recommended defensive actions

  • Verify exposure by checking if Oracle Hyperion Financial Management 11.2.26.0.000 is in use
  • Assess potential data access and integrity impacts
  • Review and implement Oracle's security patches and recommendations
  • Monitor for indicators of compromise related to this vulnerability
  • Inventory affected systems for prioritized remediation
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions, exploitation, and remediation is limited. Defenders should verify exposure and assess potential impacts with available data. Oracle Hyperion Financial Management 11.2.26.0.000 is confirmed affected; verify usage and plan for remediation. Limited source information exists on public exploitation or additional vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87174 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87174

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87174 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87174

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.