Junglewise Threat Intelligence

CVE-2026-87177: Oracle Hyperion Financial Management unauthorized access in Security component

CVE-2026-87177 · Severity: high · CVSS 8.5 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a critical financial planning and consolidation system used by enterprises to manage budgets, forecasts, and consolidated financial data. A vulnerability in the Security component allows a low-privileged attacker with network access to gain unauthorized access to sensitive financial data and modify records, potentially compromising an organization's financial records and impacting connected systems.

Technical details

This is an authorization or privilege escalation vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability has low attack complexity and requires only low-level privileges and network access via HTTP to exploit; no user interaction is required. A successful attack allows unauthorized read access to critical financial data and write access (update, insert, delete) to some accessible data. The vulnerability exhibits scope change, meaning the compromise may extend impact beyond the Hyperion Financial Management system to other connected products or infrastructure. Patches or updates should be available from Oracle's security advisories.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats