Junglewise Threat Intelligence

CVE-2026-87170: Oracle Hyperion Financial Management authentication bypass in Security component

CVE-2026-87170 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation platform used by enterprises to manage budgets, forecasts, and accounting data. A critical vulnerability allows unauthenticated attackers to gain unauthorized access to the system over the network, potentially exposing or modifying sensitive financial data, compromising data integrity, and enabling unauthorized transactions or reporting manipulation.

Technical details

This is an easily exploitable authentication bypass or access control vulnerability in the Security component of Oracle Hyperion Financial Management. The vulnerability allows unauthenticated attackers with network access via HTTP to bypass authentication controls and gain full or near-full access to the application. The vulnerability requires no user interaction and no special preconditions. A successful exploit allows attackers to create, delete, or modify critical data, as well as read all accessible application data. The affected version is 11.2.26.0.000; patches are presumed available from Oracle.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats