← back

CVE-2026-87172

CRITICAL · 9.9
hype MOSTLY HYPE · 22 hack

High CVSS alone drives sharing; no KEV, PoC, or patch advisory confirms real-world signal yet.

What: Remote code execution in Oracle Hyperion Financial Management v11.2.26.0.000 via HTTP; low-privilege network attacker can achieve full system compromise (CVSS 9.9 CRITICAL).

Why it matters: CVSS 9.9 with scope change and impact to confidentiality, integrity, and availability signals severe risk. However, no KEV listing, no confirmed PoC, and no vendor advisory or patch date disclosed yet. Social chatter is purely alert-amplification without exploitation evidence.

Where it's seen: Generic CVE alerts reposted on Bluesky; no technical PoC repositories, no defender triage reports, no Oracle patch guidance visible.

RISK: CRITICAL — CVSS 9.9, network-exploitable, low privilege barrier, scope change to dependent systems.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/16/2026, 2:23:16 AM

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS 3.1 breakdown

Exploitability 3.1 · Impact 6.0
vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High