PatchSiren cyber security CVE debrief
CVE-2026-87230 Oracle Corporation CVE debrief
The CVE-2026-87230 vulnerability affects Oracle Hyperion Financial Management, specifically component: Security, with version 11.2.26.0.000 being supported and vulnerable. This critical vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Hyperion Financial Management accessible data, as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. The CVSS 3.1 Base Score is 10.0, indicating Confidentiality and Integrity impacts
- Vendor
- Oracle Corporation
- Product
- Oracle Hyperion Financial Management
- CVSS
- CRITICAL 10
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for Oracle Hyperion Financial Management instances, especially those with network-accessible HTTP interfaces, should assess exposure and potential impact. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify exposure, assess impact, and monitor for unauthorized data modifications.
Why it matters
CVE-2026-87230 is a critical vulnerability in Oracle Hyperion Financial Management that allows unauthenticated attackers to compromise the product and access sensitive data. Defenders should prioritize verifying exposure, assessing potential impact, and monitoring for unauthorized data modifications.
- Potential unauthorized data modifications
- Possible exposure of sensitive data
- Risk of scope change impacting additional products
- Need for verification of affected versions and instances
Technical summary
A vulnerability in Oracle Hyperion Financial Management (component: Security) allows unauthenticated attackers with network access via HTTP to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Hyperion Financial Management accessible data, as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact on Oracle Hyperion Financial Management instances, especially those with network-accessible HTTP interfaces.
Recommended defensive actions
- Verify Oracle Hyperion Financial Management instances for exposure
- Assess potential impact on connected products
- Review network access controls for HTTP interfaces
- Monitor for unauthorized data modifications
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in Oracle Hyperion Financial Management. However, the scope of affected products and versions requires further verification. The vulnerability's impact on connected products and the need for verifying exposure and assessing potential impact should be considered. The official CVE Program record and NIST NVD detail page offer source-provided CVE metadata and vulnerability assessment.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87230 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87230
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87230 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87230
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.