Junglewise Threat Intelligence

CVE-2026-87179: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-87179 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is an enterprise financial planning and consolidation system used by large organizations to manage budgets, forecasts, and reporting. A vulnerability in its security component allows a low-privileged user with network access to gain complete control over the system, compromising all financial data, reports, and system operations.

Technical details

This is a privilege escalation vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability exists in the security component and is exploitable over the network via HTTP by an attacker with low-privilege credentials and no user interaction required. The flaw allows an authenticated attacker to escalate privileges and achieve full system compromise, impacting confidentiality, integrity, and availability of the application. Oracle has released security patches addressing this issue as of September 2026.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats