Junglewise Threat Intelligence

CVE-2026-87178: Oracle Hyperion Financial Management SQL injection in Security component

CVE-2026-87178 · Severity: high · CVSS 8.7 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and analysis platform used by large enterprises to manage budgets, forecasts, and financial data. This vulnerability allows a high-privileged database attacker with network access to inject SQL commands, potentially leading to unauthorized access, modification, or deletion of sensitive financial data across the system and potentially affecting other connected applications.

Technical details

A SQL injection vulnerability exists in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability is exploitable via network-accessible SQL interfaces and requires high privilege credentials to exploit. Successful exploitation grants an attacker the ability to read, modify, or delete critical financial data and other sensitive information. The vulnerability has scope change implications, meaning attacks may impact systems beyond the directly vulnerable Hyperion application. Patches are expected from Oracle's regular security update cycle.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats