PatchSiren cyber security CVE debrief
CVE-2026-87189 Oracle CVE debrief
A critical vulnerability exists in Oracle Hyperion Financial Management 11.2.26.0.000. High privileged attackers with network access via Oracle Net can easily exploit this vulnerability, potentially leading to a takeover of Oracle Hyperion Financial Management. The scope of the vulnerability may extend to impact additional products. This vulnerability is critical because it allows high privileged attackers with network access to potentially take over the system, impacting confidentiality, integrity, and availability.
- Vendor
- Oracle
- Product
- Hyperion Financial Management
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-22
Who should care
Oracle Hyperion Financial Management administrators and security teams should assess exposure and apply remediation to prevent potential takeover. Defenders should care about CVE-2026-87189 because it is a critical vulnerability in Oracle Hyperion Financial Management that allows high privileged attackers with network access to potentially take over the system, impacting confidentiality, integrity, and availability.
Why it matters
Defenders should care about CVE-2026-87189 because it is a critical vulnerability in Oracle Hyperion Financial Management that allows high privileged attackers with network access to potentially take over the system, impacting confidentiality, integrity, and availability.
- Potential takeover of Oracle Hyperion Financial Management
- Scope change impacting additional products
- High privileged attacker access via Oracle Net
- Easily exploitable vulnerability
Technical summary
The vulnerability in Oracle Hyperion Financial Management 11.2.26.0.000 allows high privileged attackers with network access via Oracle Net to compromise the system, potentially leading to a takeover. The CVSS 3.1 Base Score is 9.1, indicating critical severity. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Hyperion Financial Management.
Defensive priority
Immediate attention is required to assess exposure and apply remediation to prevent potential takeover of Oracle Hyperion Financial Management.
Recommended defensive actions
- Assess exposure of Oracle Hyperion Financial Management 11.2.26.0.000 to this vulnerability
- Apply remediation as recommended by Oracle
- Verify network access controls to limit Oracle Net access
- Monitor for potential takeover attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, its impact, and affected versions. The vulnerability has a CVSS 3.1 Base Score of 9.1, indicating critical severity. The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Hyperion Financial Management.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87189 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87189
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87189 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87189
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.