Junglewise Threat Intelligence

CVE-2026-87176: Oracle Hyperion Financial Management remote data access vulnerability

CVE-2026-87176 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and consolidation system used by enterprises to manage critical financial data. An unauthenticated remote attacker can exploit a security flaw in the product's authentication or access controls to gain unauthorized access to, modify, or delete sensitive financial data without any credentials or user interaction.

Technical details

The vulnerability exists in Oracle Hyperion Financial Management's security component and is easily exploitable via network access (TCP). An unauthenticated attacker with network connectivity can compromise the system without requiring authentication or user interaction, resulting in unauthorized read, write, and delete access to financial data. The vulnerability has a CVSS 3.1 score of 9.1 with high confidentiality and integrity impacts. Affected version: 11.2.26.0.000. Oracle has published security guidance; patch availability should be confirmed via official Oracle security advisories.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats