Junglewise Threat Intelligence

CVE-2026-87182: Oracle Hyperion Financial Management privilege escalation in Security component

CVE-2026-87182 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle Hyperion Financial Management. Vendors: Oracle.

Executive brief

Oracle Hyperion Financial Management is a financial planning and analysis platform used to manage organizational budgets and forecasts. A privilege escalation vulnerability in its Security component allows a low-privileged local user to gain full control over the application and potentially impact other connected systems. Successful exploitation could lead to unauthorized access to sensitive financial data, unauthorized modifications, and service disruption.

Technical details

This is a local privilege escalation vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000 affecting the Security component. The vulnerability requires local logon access and low-level privileges to trigger, with no additional user interaction needed. An attacker can exploit this flaw to achieve complete compromise of the Hyperion Financial Management application with scope change implications (impacts to other products). The vulnerability allows an attacker to read, modify, and delete protected data as well as deny service. A patch is expected from Oracle as part of their security update cycle.

Affected products

  • Oracle Hyperion Financial Management 11.2.26.0.000

Timeline

  • 2026-09-15: disclosed

References

Related threats