PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87189 Oracle CVE debrief

A critical vulnerability exists in Oracle Hyperion Financial Management 11.2.26.0.000. High privileged attackers with network access via Oracle Net can easily exploit this vulnerability, potentially leading to a takeover of Oracle Hyperion Financial Management. The scope of the vulnerability may extend to impact additional products. This vulnerability is critical because it allows high privileged attackers with network access to potentially take over the system, impacting confidentiality, integrity, and availability.

Vendor
Oracle
Product
Hyperion Financial Management
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-22
Advisory published
2026-09-15
Advisory updated
2026-09-22

Who should care

Oracle Hyperion Financial Management administrators and security teams should assess exposure and apply remediation to prevent potential takeover. Defenders should care about CVE-2026-87189 because it is a critical vulnerability in Oracle Hyperion Financial Management that allows high privileged attackers with network access to potentially take over the system, impacting confidentiality, integrity, and availability.

Why it matters

Defenders should care about CVE-2026-87189 because it is a critical vulnerability in Oracle Hyperion Financial Management that allows high privileged attackers with network access to potentially take over the system, impacting confidentiality, integrity, and availability.

  • Potential takeover of Oracle Hyperion Financial Management
  • Scope change impacting additional products
  • High privileged attacker access via Oracle Net
  • Easily exploitable vulnerability

Technical summary

The vulnerability in Oracle Hyperion Financial Management 11.2.26.0.000 allows high privileged attackers with network access via Oracle Net to compromise the system, potentially leading to a takeover. The CVSS 3.1 Base Score is 9.1, indicating critical severity. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Hyperion Financial Management.

Defensive priority

Immediate attention is required to assess exposure and apply remediation to prevent potential takeover of Oracle Hyperion Financial Management.

Recommended defensive actions

  • Assess exposure of Oracle Hyperion Financial Management 11.2.26.0.000 to this vulnerability
  • Apply remediation as recommended by Oracle
  • Verify network access controls to limit Oracle Net access
  • Monitor for potential takeover attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, its impact, and affected versions. The vulnerability has a CVSS 3.1 Base Score of 9.1, indicating critical severity. The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Hyperion Financial Management.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87189 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87189

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87189 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87189

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.